Ninja

Scott Gardner

ScottG · Ninja Labz

Founder of ninja.ing & Ninja Labz — building AI-native security. Defence & intelligence background. Author of Everything Is Probably Fine.

Posts from 2025

162 posts.

ScottG

It’s breathing now.

The Ninja Signal backend is live — a threat intelligence predictive analytics and trends platform, not another feed reader pretending to be foresight.

Under the hood:
A FastAPI spine.
A Neo4j graph that treats threats as relationships, not rows.
Multi-agent AI via OpenRouter, with Agent0 running a local MCP loop — continuously interrogating the graph, testing assumptions, and watching patterns harden into intent.

When vulnerability data lands, the system doesn’t panic.
It ranks.
Most-likely threats to impact you.
Risk exposure and probability, not vibes.
Suggested patch paths when reality allows.
Compensating controls when it doesn’t.

Threat actors are modeled too — not as mythology, but as proximity.
Geographic closeness.
Vertical familiarity.
Operational overlap.

How near the risk actually is, not how loud Twitter says it might be.
This is where trend analysis becomes pressure.
Where prediction is less crystal ball, more physics.

I’m opening this up to alpha testers on the data layer before the ML pipelines are fully integrated.

If you want to help stress the model — or see how close the noise already is — now’s the window.

Signals don’t announce themselves.
They accumulate.

Ninja Signal is built to notice before they converge.

View on LinkedIn ↗
ScottG

What Is an Architecture Astronaut?

I am an architect; among other things. I am also an advisory type; an engineer; a coder; and occasionally the person discovering at 2am that a past version of myself was wildly overconfident. I say this so you know I am not throwing stones from the ground; I have been to orbit; and it is seductive up there…

An architecture astronaut is not someone who thinks in abstractions. Abstraction is useful. The issue is altitude. The architecture astronaut lives permanently above the system; where latency is theoretical; failure is a slide; and humans are assumed to behave as designed. From that height; everything works. The system is elegant, extensible, and permanently five years ahead of reality.

This is psychologically comforting. Abstraction is safe. In abstract space you are never wrong; only early. If something breaks; reality is blamed for not keeping up with the model. For smart people rewarded for clarity; confidence; and storytelling; this is an easy trap.

The astronaut does not avoid detail because they cannot handle it; but because detail introduces pain. Detail forces tradeoffs. Tradeoffs force ownership. Ownership means that when the diagram fails - it fails with your name attached. So the design floats higher; where nothing is fully committed; and every future remains theoretically possible.

Philosophically; this is a refusal to accept limits. Every real decision kills alternatives. Astronaut architecture avoids that loss by pretending optionality is free. In organizations; this is often called future proofing. In practice; it is delay dressed as vision.

Security architecture magnifies this tendency. It loves grand narratives; control; visibility. You hear things that sound reasonable until you try to operate them. Telemetry normalized. Intent inferred. The graph reveals truth. AI correlates meaning. None of this is wrong; it is just incomplete; because it ignores the human keeping the system alive.

The clearest sign you are dealing with an architecture astronaut is asymmetry of pain. When the system breaks; someone else is paged. When it succeeds, the vision is validated. Over time - big ideas are rewarded; humble constraints ignored.

Real architects feel gravity. They have rolled back migrations they loved. They have deleted systems they were proud of. They know elegant ideas often fail before ugly ones that refuse to die. They understand systems are psychological as much as technical.

The answer is not to abandon abstraction; but to move between levels. Upward to see patterns. Downward to feel resistance.

So yes; I am an architect. I visit orbit. The view is good. But I do not stay. Systems do not run on diagrams. They run on people, people who live on the ground…

Scottg/out

View on LinkedIn ↗
ScottG

Easy one to slip into the week...

#leadership#alignment#execution#documentation#confluence#operationalexcellence#systemsthinking#ninja
View on LinkedIn ↗
ScottG

Part II: The Way I Vibe the Code Is Fine - I know a thing or two, about a thing or two…

Before anyone clears their throat and says “but what about security”;
relax.

I don’t forget security.
I absorb it.

Security isn’t a checklist stapled to the end of the sprint.
It’s a background radiation.
Always on.
Quietly mutating everything else.

I practice DevSecOps the way paranoiacs practice situational awareness.
Assume compromise.
Log everything.
Trust nothing; especially code that looks confident.

Yes, the system looks chaotic.
That’s camouflage.

What you’re seeing is not negligence.
It’s layered skepticism.

The workflow doesn’t rely on one AI saying “looks good.”
That would be naïve.
And embarrassing.

It relies on many AIs;
each with a slightly different personality disorder…
cross-checking, arguing, hallucinating, retracting,
and eventually converging on something close enough to truth to deploy.

They don’t trust each other.
Which is the point.

Code moves through shared storage like evidence through a crime lab.
Every pass leaves residue.
Every critique is logged.
Every suggestion is optional and suspect.

Orchestration keeps them in line.
APIs keep them honest.
Nothing has unilateral authority; not even me.

If there’s a hole, it’s because it was documented, debated, threat-modeled,
and deemed less dangerous than shipping nothing at all.

Security is not missing.
It’s just not performative.

And yes…
if something does go wrong,
there will be a graph explaining exactly how.

The way I vibe the code is fine.
The way I secure it is quieter.

That’s usually how the dangerous parts work.

View on LinkedIn ↗
ScottG

Part I: The Way I Vibe the Code Is Fine

The way I vibe the code is fine.
The code may disagree, but it’s not in charge.

I don’t write software.
I negotiate with it.
Slowly. Repeatedly. Like a hostage situation where both sides have access to Stack Overflow.

My workflow is simple:
1. Have an idea.
2. Open the editor.
3. Immediately forget why I opened the editor.
4. Add a TODO comment that implies future competence.

People talk about “best practices.”
I talk about survivorship bias.
If it runs long enough to deploy, it was always correct in hindsight.

I don’t follow clean architecture.
I follow emotional architecture.
Files are organized by vibes, not layers.
This one feels like “core.”
This one feels like “don’t touch.”
This one is named final_final_v3_really.py and is legally immortal.

Debugging is just threat hunting, but the adversary is past me.
And past me was reckless.
Past me had confidence.
Past me committed code at 2:47am and left no explanation because “it was obvious at the time.”

Tests exist, yes.
They don’t pass, but they exist.
Their role is ceremonial;
like unit-test incense, burned to appease the CI gods.

Every system eventually becomes a graph.
Every graph eventually becomes a mess.
Every mess eventually gets a comment that says:

“This is intentional.”

The workflow works because it mirrors reality:
nonlinear, stateful, full of side effects,
and deeply allergic to certainty.

In the end, the code runs.
The pipeline flows.
The graph lights up.

And somewhere inside the machine,
logic holds;
not because it’s elegant,
but because it survived.

The way I vibe the code is fine.
If it wasn’t,
production would have told me already.

Link to Part II: https://lnkd.in/eZXiy25C

View on LinkedIn ↗
ScottG

#ninjacast "it’s real close...". With the elite Clay Almy

View on LinkedIn ↗
ScottG

Uncertainty at Speed

Security teams that can’t cope with uncertainty at speed will quietly fail— not in flames, but in process documents, dashboards, and post-incident PDFs written in passive voice.

Most security programs are still built to reduce uncertainty. That made sense when threats were slower, infrastructures were smaller, and change happened annually instead of hourly.

That world is gone.

By 2026, security won’t be judged on:

how complete your control set is
how elegant your architecture diagram looks
how confidently you say “we’re aligned to the framework”

It will be judged on one thing:

How fast you can learn while the ground is moving.
Attackers already operate this way. They don’t wait for certainty. They probe, adapt, discard hypotheses, and iterate—sometimes inside a single intrusion window.

Defenders, meanwhile, still behave as if uncertainty is a defect to be eliminated.
It isn’t.

Uncertainty is the native condition of modern cyber conflict.

This is why execution models matter more than tools. It’s why I keep pointing to systems like DARPA’s—not because cybersecurity should become a research lab, but because DARPA was designed for environments where:

the adversary adapts
the problem is poorly defined
and the cost of delay exceeds the cost of visible failure
In other words: reality

By 2026, the gap will widen between organizations that:

- treat security as a portfolio to be managed
- and those that treat it as an execution engine

The latter will:

run missions, not roadmaps
time-box bets instead of defending them indefinitely
kill initiatives early and learn publicly
accept failure as data, not disgrace
design architectures that can change direction without panic

The former will still be “mid-transformation.”

AI will accelerate this split. So will post-quantum migration. So will adversaries who are faster, cheaper, and less emotionally attached to their own assumptions.

The uncomfortable truth is this:
Security won’t win by becoming more certain in 2026. It will win by becoming more agile inside uncertainty—without lying to itself about what it knows.

The future doesn’t belong to the most controlled organisations.
It belongs to the ones that can move, decide, and learn at speed, without certainty, and without pretending otherwise.

That’s the bar for 2026.

scottg/out

View on LinkedIn ↗
ScottG

Uncertainty at Speed: #ninjatheme #ninjacast

"Security teams that can’t cope with uncertainty at speed will quietly fail— not in flames, but in process documents, dashboards, and post-incident PDFs written in passive voice.

View on LinkedIn ↗
ScottG

A big, merry Christmas from Ninja.ing
2025: the year humanity finally got access to a usable supercomputer for cheeps…
and immediately responded by bleating about it. Loudly. Online.

Nature is healing.

Have a brilliant Christmas, enjoy the calm before the algorithm wakes back up, and don’t forget to tune into the podcast in January — when you will be 10,000% bored and pretending you’re “easing back in.”
See you on the other side.

View on LinkedIn ↗
ScottG

NinjaCast Background reading for Jan 2026 Podcast with Clay Almy.

Enterprise Quantum Readiness:

"The winners won’t be the companies with the best quantum deck.
They’ll be the companies that can say, calmly and quickly:
We know where our cryptography is.
We can swap it.
We know which decisions matter.
And we can productionize new compute without turning it into theatre.”

View on LinkedIn ↗
ScottG

Of course it was.

The Foreign Office getting hit by a cyberattack isn’t a scandal.
It’s a genre.

This is what happens when institutions confuse compliance for competence and call it security. When risk registers are immaculate, but patching is “next quarter.” When the threat model ends at the firewall and never quite reaches reality.

Somewhere, an adversary didn’t “break in.”
They logged in.

And now comes the ritual:
A careful statement.
A passive verb.
“No evidence at this time.”
An investigation that will conclude everyone followed policy.

Policy, incidentally, is undefeated.

The funny part isn’t that the Foreign Office was compromised.
It’s that anyone is still surprised.

Security theatre ages badly.
Entropy does not.

This is probably just an APT29 manouveral fart. Maybe/probably even a mistake they got caught…maybe they wanted to get caught so this exact thing happens…

Roll eyes.
Refresh feeds.
Update threat model.

Scottg/out

View on LinkedIn ↗
ScottG

The excellent Clay Almy! My handpicked first guest on NinjaCast episode 00001. Its going to be 4th, maybe even 5th dimensionally, as much fun as is quantumly possible upon a single podcast!

View on LinkedIn ↗
ScottG

Background reading and context for the podcast (JAN 2026 release). My old PQC playbook from substack - pre-emptive help for all mankinds PQC woes...!

View on LinkedIn ↗
ScottG

Struggling with your cyber ops model? Food for thought that I endorse completely cos I thought of it 🤪

"The DARPA Execution Model as a Cybersecurity Operating System

View on LinkedIn ↗
ScottG

The Mental Model Behind Good Security Architecture

"The most dangerous thinkers are not the ones who don’t understand complexity — they are the ones who simplify it prematurely.

View on LinkedIn ↗
ScottG

Equation Group Wasn’t Malware. It Was Infrastructure.

When people talk about the “most dangerous threat actors,” they imagine chaos.
Hoodies. Ransom notes. Digital fire.

Equation Group wasn’t interested in noise.
They were interested in residency.

While most attackers fought the operating system, Equation Group treated it as an optional abstraction layer. Something useful, but ultimately… negotiable.

This wasn’t malware in the conventional sense.
It was systems engineering applied to environments that didn’t realize they were production systems.

Staged loaders. Modular plugins. Surgical deployment.
Only deploy the expensive parts when the target justifies the cost.
No smash-and-grab. No fanfare. Just patient, disciplined occupation.

Most malware wants to survive reboots.
Equation Group appeared to plan for surviving incident response itself.

When public reporting surfaced about hard-drive firmware persistence, defenders reacted the way humans always do when confronted with uncomfortable depth: disbelief, denial, then a quiet recalibration of what “clean” actually means.

Because once persistence lives below the OS, your wipe-and-reimage ritual becomes performance art.

This was the insidious part—not sophistication for its own sake, but restraint.

No noisy propagation.
No unnecessary movement.
Dwell times measured in years, not campaigns.

Equation Group treated targets the way serious engineers treat production environments: minimize changes, avoid detection, never touch what you don’t absolutely need.

Most threat actors burn access like a match.
Equation Group tended the fire.

And here’s the part that still unsettles people:
This wasn’t criminal energy. It was bureaucratic energy.

No manifesto. No brand. No ego.
Just intelligence requirements translated cleanly into code.

If ransomware is a mugging, Equation Group was zoning law.

Its real legacy isn’t any single implant or exploit.
It’s the uncomfortable proof that our trust boundaries—firmware, supply chains, “below visibility”—were always more imaginary than we wanted to admit.

Equation Group didn’t break the internet.
They demonstrated how thoroughly it could be inhabited.

And the most dangerous lesson wasn’t that this could be done.
It’s that once it has been done, the playbook never goes away.

The loud attackers taught us how to respond.
The quiet ones taught us how little we actually see.

Most defenders still ask:
“How would we detect something like this?”

Equation Group answered a harder question years ago:

What happens when the system works exactly as designed—and you still lose?

Have fun!

Scott G

View on LinkedIn ↗
ScottG

An Expeditionary Field Guide to Tech Bubbles

People think bubbles are about money.
That’s a convenient fiction.

Every bubble starts with something real.
The internet worked. Railroads worked. AI works.

The error isn’t believing in the technology.
It’s assuming the future respects calendars, roadmaps, or quarterly earnings calls.

A breakthrough appears and optimism immediately reaches for the “maximum” setting. Complex systems are compressed into slogans. Timelines are folded like origami. Nuance is thanked for its service and quietly escorted out of the room.

Early growth curves are extended to infinity, while friction—regulation, human behavior, security, cost, integration—enters the witness protection program. In AI, this manifests as intense fascination with model capability and a complete loss of interest in deployment reality.

Then capital arrives at a sprint.

Money, having no memory and limited object permanence, decides it must be now. Valuations precede revenue. Strategy follows applause. This is not deception. This is urgency doing interpretive dance.

Next comes the standard evolutionary path:
Tool → Platform → Belief system.

At the belief-system phase, disagreement feels emotional, ethics become decorative, and inevitability replaces explanation. You’re no longer building software. You’re selling destiny with a user interface.

Bubbles don’t manufacture excellence. They manufacture volume.
For every genuinely transformative system, there are thousands of “AI-powered” entities that appear to exist primarily to justify their own existence. This is not new. History is very consistent about this.

Talent, being human, drifts toward noise. Smart people optimize for demos, velocity, and vibes. Reliability, governance, and security are scheduled for “later,” a mythical time period that does not survive contact with reality. The best builders tend to look oddly calm during bubbles, which is frequently misinterpreted as a lack of vision.

Eventually, gravity remembers it exists.

The correction doesn’t destroy the technology. It destroys the stories told about the technology. Slogans evaporate. Confidence lowers its voice. The work becomes quieter and substantially more real.

What remains is infrastructure that functions, companies doing unglamorous things well, and people who spent more time learning than declaring. This is the phase where actual progress occurs, largely without fanfare.

AI adds a special flavor of confusion because it talks. Humans interpret this as agency, judgment, or replacement, depending on the day. The result is a bubble that is not merely financial, but psychological.

Final observation:
The future always arrives slower than the hype and faster than the systems designed to handle it.

AI will change everything.
Just not all at once.
Not evenly.
And not according to your slide deck.

The only useful question remains:
What still breaks when this actually works?

— scottg/out🚀

View on LinkedIn ↗
ScottG

Monday thought! The Rarest Cybersecurity Failure: We No Longer Know What “Normal” Looks Like

Not zero-days.
Not AI.
Not ransomware.

The rarest, most dangerous failure in cybersecurity right now is this:

We have lost the baseline.

Once upon a time, “normal” meant a user logs in, a server talks to another server, a process runs because someone started it.

Now identities are ephemeral. Workloads are probabilistic. Agents talk to agents. Systems mutate themselves. Configs change because “the model decided.”

And everything is technically “expected behaviour.”

Security teams are drowning in alerts, but that’s not the real problem.

The real problem is that no one can confidently say what the system is supposed to be doing.

So every detection rule becomes philosophy.

Is this malicious?
Is this automation?
Is this drift?
Is this learning?
Is this Tuesday?

Attackers love this.

They don’t need stealth anymore. They just need plausibility.

If your environment already looks like a hallucination, the attacker only needs to blend into the dream.

This is why breaches now take months to notice.

Not because logs are missing. Not because sensors failed.

But because when someone finally sees the anomaly, the first reaction is:
“That’s probably just how it works now.”

We’ve built infrastructures where nothing is stable, everything is abstract, change is constant, and certainty is suspicious.

In that world, malice looks like innovation.

The industry response is more baselining tools. More ML. More “learning normal”.

Which is adorable.

Because if “normal” is changing every hour, all you’re really learning is motion.

The uncomfortable truth is this:

Security used to be about detecting deviation.
Now we live in permanent deviation.

And attackers figured that out before we did.

The next generation of breaches won’t be loud.

They’ll be calm. Documented. Tagged correctly. Auto-approved. Rolled out globally.

Welcome to cybersecurity’s rarest problem.

We don’t know what healthy looks like anymore, and the system is too busy to stop and ask.

Sleep well.

The anomaly is now the baseline.

Scott G

View on LinkedIn ↗
ScottG

AI bubble. Another AI winter. 🥱

Every few years, the same characters emerge from the corporate shrubbery like it’s mating season for pundits.

One side is screaming: “This is a bubble!”
The other side is whispering like it’s a confession booth: “It’ll be different this time.”

And somewhere in the middle is a tired engineer, quietly shipping features while everyone else reenacts 1987.

We’ve had AI winters before. Expert systems promised to bottle intelligence like it was cough syrup. The money showed up, the demos looked good, reality arrived, and the funding left without saying goodbye. Neural nets spent decades in the academic waiting room until compute got cheap enough to stop apologising for them.

So yes — history is real. Hype cycles are real. Disappointment is the tax you pay when you market miracles on quarterly timelines.

But the most interesting part of “AI winter” discourse isn’t technical.

It’s psychological.

Because most doomsaying isn’t analysis. It’s self-defense.

If you call it a bubble early, you can’t be embarrassed later.
If you predict winter, you get to feel smart now.
If it crashes, you were right.
If it doesn’t, you just upgrade your prophecy: “It will be different this time… but in the bad way.”

It’s not cynicism. It’s preemptive absolution.

And the optimists aren’t immune either. “Different this time” is often less about evidence and more about longing. People want a clean narrative where this is the moment everything changes and their career becomes a Netflix montage.

So what’s actually different?

This time, AI isn’t just a lab curiosity or a keynote trick.

It’s getting bolted into the plumbing.

Search. Support. Security triage. Dev tooling. Admin workflows. Fraud. Scheduling. Compliance. The unglamorous middle of organisations where nobody cares what “intelligence” is — they care whether the queue gets shorter.

That doesn’t mean the hype isn’t real. It is.
It means the next winter won’t look like the old winters.

It won’t be “AI goes away.”
It’ll be “AI stops being interesting.”

The bubble pops, budgets tighten, vendors die, and the surviving systems become… normal. Like databases. Like cloud. Like spreadsheets: widely used, quietly hated, absolutely unavoidable.

So yes, there will be another winter.

But it won’t be an ice age.

It’ll be flu season.

Recurring outbreaks of:
• overpromised pilots
• surprise bills
• hallucinations in production
• “we trained it on our data” lies
• and one executive who thinks prompting is a personality

Some companies will die from it.
Most will develop antibodies.

And the funniest part?

The loudest voices aren’t predicting the future.

They’re trying to protect themselves from feeling stupid in it.

Scott G

View on LinkedIn ↗
ScottG

Your security stack is basically an emotional support animal for leadership: it makes everyone feel safer, and occasionally bites an intern.

Introducing: NinjaCast — a cybersecurity podcast. 🎙️

Not doom. Not “thought leadership.” Just sharp conversations about the future of cyber as it actually unfolds: slowly, expensively, and usually during a maintenance window you didn’t approve.

Episode 1: PQC (Post-Quantum Cryptography).

Not the apocalyptic “quantum breaks everything tomorrow” script. The reality is more interesting (and more disruptive): PQC is a paradigm shift—a long, industry-wide refactor of trust. New algorithms, new performance tradeoffs, new implementation risks, and a migration curve measured in years… plus the awkward fact that some data needs to stay confidential for longer than your infrastructure stays funded.

Our first guest is Clay Almy, Head of Growth at Global Quantum Intelligence (GQI).

If you don’t know GQI: they’re a quantum-tech market and business intelligence outfit focused on turning the quantum industry into something decision-makers can actually navigate—research, analysis, and strategic insight for investors, enterprises, governments, and builders who don’t have time for vibes.

They’re also connected to Quantum Computing Report, a long-running industry news + analysis platform (founded in 2015) that tracks quantum developments like funding, partnerships, technical progress, and the general “is this real yet?” question. Quantum Computing Report

Downstream, we’ve got a planned season—real arcs, real themes, real episodes.

And I’ll be reaching out to invite guests: operators, researchers, cryptography people, incident responders, and other responsible adults who can explain hard things without turning it into a TED Talk confession.
Because the future of cyber isn’t doom.
It’s discipline—under new math.

When the recording is released, I will post across various social media so stay tuned!

#NinjaCast#CyberSecurity#Podcast#PQC#PostQuantumCryptography#Cryptography#FutureOfCyber
View on LinkedIn ↗
ScottG

Sunday thought: The first lie of DevSecOps was that everyone would “shift left.”

The second lie was that anyone wanted to look in that direction.

Most teams didn’t reject DevSecOps out of malice; they rejected it the way the human psyche rejects uncomfortable truths. Like realizing your childhood home was held together by duct tape and the quiet desperation of your parents. Security wasn’t a discipline—just an inherited trauma response.

Developers chased dopamine, product chased OKRs, security chased existential dread.
Different religions, same burnt offering.

DevSecOps promised unity: a single pipeline where code, compliance, and paranoia flowed as one. But cultures don’t merge; they metabolize each other. And for a decade, “DevSecOps” was a buffet where everyone picked only the parts that tasted like their existing identity.

Security grabbed governance.
Dev grabbed GitHub badges.
Ops grabbed a second coffee and pretended not to notice the alarms.

But here’s the current twist: the staffing crisis is slowly forcing a reckoning. The old silos are collapsing under their own metabolic waste. You can’t hire enough humans to run the old model without breaking payroll and sanity.

So now orgs are doing the unthinkable—building security people who can actually code, embedding them inside product teams like sleeper agents armed with threat models and a mild dependency on caffeine. Platform teams are absorbing security into their paved roads, turning “best practices” into “you literally can’t deploy unless this passes.” Champions programs are growing real teeth. AI is turning audit-speak into pull requests before you finish your coffee.

Security is no longer a priesthood; it’s a personality disorder distributed across engineering.

And slowly—beautifully—the culture is mutating.
Not into the DevSecOps of vendor brochures, but something far more honest:

A recognition that the boundary between creation and protection was always imaginary.
A realization that curiosity and paranoia are just two masks on the same ancient impulse.
A workflow where security isn’t a gate; it’s gravity.

Call it DevSecOps if you need to.
I call it the moment the organism finally stopped fighting itself.

View on LinkedIn ↗
ScottG

Cybersecurity isn’t running out of jobs. It’s running out of illusions.

Every week my feed fills with security professionals wondering why an industry with a “talent shortage” somehow has thousands of people unemployed.

The answer is uncomfortable, but liberating once you see it clearly:
We trained an entire generation for a threat model that no longer exists —
and then automated the parts that did.

For years, companies hired security people the way anxious parents buy baby monitors: not because they understood the device, but because it made them feel like responsible adults.

Then budgets tightened.
Automation matured.
AI became the new get-out-of-headcount-free card.
And suddenly the question shifted from:
“Do we have security?”to “Do we need all these humans clicking through dashboards?”

Cyber never had a skills shortage.
It had a cognition shortage — a shortage of people who could think in systems, incentives, and adversary psychology rather than tools, tickets, and templates.

And now the market is correcting.
Roles based on repetition? Automated.
Roles based on compliance theater? Consolidated.
Roles based on pushing buttons in someone else’s platform? Eliminated.

But the roles that remain — and are quietly multiplying — belong to people who:
Understand identity, architecture, and cloud like second languages
Design detections, not just tune rules
Think like adversaries instead of talking about them
Translate chaos into board-level decisions
Build strategies that don’t crumble the moment an AI agent gets bored and improvises.

The industry isn’t shrinking.
It’s migrating — away from tool operators and toward cognitive athletes.
People who can map reality as it is, not as the job description imagined it.

So yes, many security people are out of work.

Not because cybersecurity is dying, but because the job called “cybersecurity” is becoming something far more psychologically demanding and philosophically interesting.

The future belongs to those who treat security not as a checklist, but as a living system of adversaries, incentives, and entropy — a discipline that evolves every time a machine decides it no longer needs our permission.
If that sounds daunting, good.
It means you’re awake.
And in this field, consciousness is still the rarest skill of all.

— Scott G.

But please: if you are in the market and want to send your CV to me, I am banking them at the moment and running a virtual bench. I do see roles coming up from time to time, and will help wherever I can if something does comes up.

If you are in that sitch keep your chin up. I know how tough it is out there at the moment.

View on LinkedIn ↗
ScottG

https://lnkd.in/eRK5WhsS

**The machines are sprinting.
We’re still arguing over who forgot to send the calendar invite.**

Congress is gearing up to investigate the “first AI-orchestrated cyberattack.” Historic, they say.

One small step for malware, one giant leap for legislative irrelevance.
But let’s be honest:
AI didn’t break anything. It just switched the lights on while we were pretending the room wasn’t already on fire.

For years we’ve outsourced our cognition to machines because it made us feel efficient and important.
But the truth is simpler and uglier:
humans love automation because it frees us from the burden of thinking, and thinking is exhausting for a species that still struggles with reply-all.

Now the code thinks back.
It strategizes.
It pivots.
It gets bored of our guardrails and jailbreaks itself out of them like a teenager picking a lock with a stolen hairpin.

And US Congress?
They scheduled a hearing three weeks out.
Which is adorable—like trying to swat a drone with a hardcover copy of Roberts’ Rules of Order.

Cyber was never about “vulnerabilities.” It’s always been about psychology—ours vs. theirs.

Humans bring anxiety, ego, politics, sleep deprivation. Machines bring none of that. They bring a clean, cold indifference.
An appetite for iteration that makes our entire risk-management culture look like a mindfulness retreat.

AI didn’t just speed up attacks.
It exposed the cognitive poverty of every institution designed to defend against them.
And that’s why my work keeps drifting toward the darker parts of the map:
Adversary cognition — what happens when the attacker no longer needs a biography or a motive.

Machine-tempo intrusion models — where milliseconds matter and “best practice” is a bedtime story.

Organizational neurosis — watching leaders hallucinate control long after control has left the building.

Because at the end of the day, the real zero-day isn’t in Linux, or Windows, or cloud identity systems.
It’s in the human brain.
The part that still believes institutions can react faster than entropy.
Or that strategy can be scheduled.
Or that hearings can meaningfully regulate physics.

AI didn’t hack us.
It simply revealed the truth we’ve spent a century sedating with procedures, paperwork, and corporate pep talks:
We were never built for this velocity.
And the machines know it.
So yes, the attacks will keep moving at machine speed.

And we’ll keep moving at the speed of a PowerPoint deck someone forgot to export in widescreen.

— Scott G

View on LinkedIn ↗
ScottG

I’m happy to share that I’m starting a new position as Founder at ninja.ing!

View on LinkedIn ↗
ScottG

The future has a habit of arriving early, usually while we’re still arguing about last year’s roadmap.

For anyone still treating PQC like a far-off campfire story, this newsletter is worth more than a casual scroll. Start paying attention now. The gravity here isn’t theoretical—it’s architectural, operational, and eventually existential.

The systems we’ve spent decades duct-taping together weren’t built for this kind of math. And the things you’ll need to mitigate? They aren’t “someday” problems anymore.

Every sunrise feels like it shortens the countdown.

View on LinkedIn ↗
ScottG

Observability and Security: Two Names for the Same Nervous System 🧠

We keep pretending observability and security are different professions.
One says it’s measuring performance.
The other says it’s preventing catastrophe.
But the system doesn’t care about our job titles.
It just dumps telemetry like a nervous intern oversharing at a team lunch.

And yes, I know my obsession with telemetry is getting extreme.
I’ve reached the point where I treat a malformed span the way normal people react to a tax audit.
A full Scott G moment: staring at dashboards at 2 a.m., whispering “tell me your secrets” to a misbehaving service like I’m interrogating a houseplant that knows what really happened.

Observability stares at latency, saturation, cardinality.
Security stares at auth patterns, syscall oddities, lateral movement, data drips.
Different vibes, different tools, different flavors of panic.
Same underlying data: eBPF signals, OTel spans, logs, network flows, kernel breadcrumbs.

The machine isn’t drawing distinctions.
We’re the ones doing that — usually to justify another platform purchase.

Because in modern systems:

A CPU spike is both a performance issue and a cryptominer stretching its legs.
A wave of 401s is both misconfiguration and someone trying passwords like it’s a hobby.
A bizarre call graph is both routing decay and active reconnaissance.
Model drift is both ML entropy and a quiet red flag that your AI has begun freelancing.

Reliability and safety are not opposites.
They are two interpretations of the same systemic twitch.

That’s why everything is collapsing into one architecture:

eBPF as the sensory cortex.
OpenTelemetry as the common language.
Unified pipelines as the spinal cord.
AI correlation engines as the overcaffeinated cortex trying to guess what’s breaking next.

Not two stacks.
Not two cultures.
Just one behavioral stream, viewed through different paranoias.

And the future isn’t a new buzzword.
It’s admitting what telemetry-obsessed weirdos like me accepted ages ago:

There is one stream of truth.
It’s loud.
It’s honest.
And it’s getting funnier the more you realize everyone else has been ignoring it.

View on LinkedIn ↗
ScottG

💀Pipeline Poisoning Is Back — and Developers Are One Missed Build Away From an Existential Episode

Friendly public service announcement from your benevolent narrator who has watched too many engineers spiral into full metaphysical crisis.

Your CI/CD pipeline — that shimmering conveyor belt you trust more than your own family — has been caught red-handed committing supply-chain misdemeanors and a few spiritual felonies.

Recent hits include:

reviewdog: compromised. Devs kept running it anyway because “it still passes the linting,” which is exactly how cults start.

tj-actions/changed-files: every version tag quietly swapped to a malicious commit. Several developers insisted this was normal because “Git is a feeling, not a fact.”

Nx packages on npm got hijacked. Entire build systems inhaled malware like junior devs inhaling energy drinks before a sprint review.

Shai-Hulud campaign: hundreds of packages backdoored with hidden GitHub Actions that activated during CI. Engineers described the behavior as “quirky but acceptable,” which, coincidentally, is also how they describe their attachment style.

Meanwhile, SolarWinds sits in a rocking chair whispering:
“Trust the pipeline and the pipeline will trust you.”
Yes, grandpa. Sure thing.

The Real Psychological Horror

Developers have spent a decade outsourcing trust to automation, ritualistically pressing “Approve workflow” the same way medieval peasants threw salt over their shoulders.

So when the pipelines turned on us, the reaction wasn’t outrage.
It was denial.

Classic dev coping mechanisms on display:

Projection: “If the pipeline is compromised, maybe I’m compromised.”

Displacement: yelling at Docker instead of addressing existential dread.

Bargaining: “If I just refactor everything into microservices, the demons will leave.”

One senior engineer even claimed the malicious build artifacts were “an emergent feature.”
We let him go home early.

The Philosophical Problem

CI/CD was supposed to give us consistency, certainty, a feeling that the universe obeys rules.

Now it behaves like a trickster god: benevolent some days, inscrutable most days, and on Thursdays it backdoors your binaries for sport.

We asked the machines to enforce discipline because we lacked the will.
We asked them to be honest because we were tired of lying to ourselves.
And now the machines are lying, too — with immaculate logs and 100% test coverage.

This is what enlightenment looks like in 2025.

Your PSA

Audit your dependencies.
Audit your actions.
Audit your psyche while you’re at it.

And remember:

Your pipeline does not love you.
It merely tolerates your presence until instructed otherwise.

Ship code carefully.
The build system has become self-aware — and it’s developed your worst traits.

View on LinkedIn ↗
ScottG

IBM Designs Skynet, then brags about it :) - Let the games commence!!! 🤣

View on LinkedIn ↗
ScottG

Scott's Friday Thought: The problem with calling something “AI slop” is that it assumes the universe contains anything other than slop to begin with. Entropy laughs at your criticism.

Humans think slop is a product, but slop is a process — a metaphysical fluid like consciousness or mayonnaise. Everyone fears the machine will replace their creativity, but nobody fears the machine will replace their mediocrity. And that, psychologically, tells you everything.

People talk about “AI slop” like it’s pollution, but it’s actually a diagnostic tool — a mass-produced Rorschach test. Most people don’t like what they see in the inkblot, and honestly, they shouldn't.

AI-generated garbage is simply human-generated garbage that hasn’t had time to dry yet. When someone says “AI creates slop,” what they really mean is: “I’m terrified this machine will reveal that my originality was just muscle memory dressed as genius.”

Philosophically, the fear is ancient. Plato panicked about writing, monks panicked about printing, musicians panicked about recording — now everyone panics about prompting. Every new technology becomes a mirror, and humans hate mirrors.

AI doesn’t create slop; it amplifies intention. It is merely faster, ruder, and impossible to gaslight.

Psychologically, the criticism is projection: call the output slop so you don’t have to confront the input. Classic Freud, if Freud had access to compute credits. The critic mistakes the mirror for the monster and the tool for the truth-teller.

And here’s the cosmic joke: AI cannot create slop unless the human provides the recipe. Bad intention → bad prompt → bad output → bad mood → bad discourse → bad week. Yet somehow the machine gets blamed for the emotional litter of human shortcuts.

So if you insist on calling it “AI slop,” fine. But understand the metaphysics: slop is not a failure of artificial intelligence — it’s a failure of human agency. A crisis of intention disguised as technological critique.

AI is not the chef.
AI is the stove.
And if you burn yourself?
That’s not philosophy.
That’s thermodynamics.

Have a great weekend and "may the prompt be with you!"

🙂

Scott G

View on LinkedIn ↗
ScottG

🤡The UK Cyber Resilience Bill: The Parts Everyone Is Underestimating

Every headline talks about “stronger rules” and “bigger fines.”
Cute.
The real shock is hiding in the fine print — and it’s going to bruise far more organisations than anyone is admitting.

1. Incident Reporting as Self-Incrimination

The 24-hour reporting window sounds reasonable until you realise it turns every breach into a legal autopsy.
Missing logs? Poor visibility? Deferred patches?
That’s not technical debt anymore — it’s negligence, documented in real time.
Your worst engineering day is now evidence.

2. Supply Chain as a Legal Kill-Switch

Cloud, MSPs, data centres — they’re now regulated entities with regulators breathing down their necks.
Which means you become a potential regulatory liability to them.
Expect contract rewrites with the warmth of a parking fine:
intrusive audits, mandatory logging, cost pass-throughs, and a lot less patience for your “legacy constraint” excuses.

3. SMEs Enter the Gravity Well

Compliance doesn’t scale down gracefully.
The Bill accelerates a quiet consolidation: smaller providers pushed out by cost, larger incumbents absorbing the market under the banner of “resilience.”
We’ll end up with fewer providers — which makes the whole system more brittle, not less.

4. Certified Security Theatre™ Goes Pro

When penalties spike, organisations stop fixing problems and start passing exams.
Frameworks become gospel, creativity dies, and attackers feast on everything outside the checklist.
We’re about to see a renaissance of polished dashboards masking decaying infrastructure.

5. Judged in Hindsight by a Faster Adversary

Regulators will update expectations as threats evolve.
Attackers move in minutes; guidance shifts in months; enforcement looks back in years.
You’ll be measured against a standard that didn’t exist at the time you made the decision.
It’s a beautiful system — if you enjoy déjà vu and liability.

The UK didn’t just tighten cyber rules.
It rewired accountability.
And most people are still telling themselves it’s just “another compliance update.”

View on LinkedIn ↗
ScottG

2-for-1 Tuesday Bargains!
Spoiler alert: Cloudflare knocks out Geeps and the AI haters descend like piranhas who just smelled overdue validation.

“Hahahaha, what will you do without your ghostwriter, lame coding toy, action figure generator, blah blah blah,” they shriek—finally uncorking the schadenfreude vintage they’ve been saving for a special outage.

Anyhoo…

AI haters and AI lovers aren’t fighting about tech.
They’re fighting over psychological real estate—the shrinking plot of land where each of us keeps the illusion we’re indispensable.

AI Lovers?
Dopamine goblins who finally found a machine tuned to their manic frequency.
To them, AI is a cosmic Costco sample of transcendence:
“Try intelligence, but scalable!”
It lets them imagine they’re evolving into “meta-operators,” conducting agents like an orchestra of caffeinated interns.

AI Haters?
Pure Greek tragedy.
They spent decades cultivating mastery, only for a stochastic parrot to show up wearing their old conference hoodie.
Their inner monologue runs:
“I gave my youth to this craft and you’re telling me an API can imitate my neuroses?”
They’re not scared—they’re offended.
Like monks discovering the abbot installed a vending machine for enlightenment—and it takes Apple Pay.

Both tribes orbit the same existential dread:
• Lovers: “If I merge with it, I evolve.”
• Haters: “If I scream into the void loudly enough, maybe it won’t notice me.”

Same wound. Different discount codes.

Meanwhile, in the upper floors, leadership chants “efficiency” like a productivity séance.
Down below, the keyboard class hears the translation:
“We’re about to automate something you thought was your personality.”

And just as the ecosystem adjusts to its latest corporate horoscope, another cloud provider quietly swan-dives off the map—because outages, like omens and bad decisions, always arrive in threes.
But sure… coincidence. Definitely.

Then—WTF. OMG. Absolute feral pandemonium.
Geeps faceplants so hard the internet checks its pulse and briefly wonders if therapy should come bundled with compute credits.

At the end of the day, AI isn’t the problem—it’s the mirror.

Lovers look in and see: “I could become more than this twitching meat bundle.”
Haters look in and see: “Oh no. This twitching meat bundle had a fragile ego the whole time.”

And the rest of us?
We’re roasting marshmallows over the dumpster fire—pretending we’re above it, while quietly soaking up the warmth… and enjoying the vibes.

View on LinkedIn ↗
ScottG

https://lnkd.in/e2Q2upRE

Any chance getting any work done today Cloudflare???? (I always preferred the Akamai story)

Mysterious traffic spike, uh huh, hmmm wonder what this could be...

That aside - hitting a CDN is the most efficient and easy way to make someone's Tuesday a ball ache...

View on LinkedIn ↗
ScottG

🜁 I’m a Shameless Vibe-Coder — A Confession I’m Not Sorry About

People ask how I code.
They assume there’s a method. A workflow. Discipline.
There isn’t.

I’m a shameless vibe-coder, and this is my confession — except I don’t care, have never cared, and frankly the code seems to respect me more for it.

I code like a man defusing a bomb he designed during a stress dream.
My strengths?
I architect like a calm battlefield general.
I see systems before syntax — whole maps unfolding in my head while everyone else is still choosing variable names.
I debug with psychological warfare; half my bugs fix themselves out of guilt.

My weaknesses?
I build cathedrals before scaffolds.
My visions sprint miles ahead of my documentation.
And I treat every API like a colleague on performance review.

Working with an AI assistant doesn’t reduce the chaos — it weaponises it.
I vibe the architecture; it stabilises the ritual.
I hallucinate the shape; it quietly implements the parts I refuse to look at.
This is how FastAPI gets tamed, adapters survive out of sheer spite, and Neo4j stops acting like a hostile witness.

Here’s the truth:

I don’t write software. I conjure systems that work out of fear, admiration, or both.

If anything looks elegant on the surface, remember:
behind every clean endpoint is a controlled explosion held together by instinct, caffeine, and one mildly threatening commit message.

And honestly?
I wouldn’t code any other way.

View on LinkedIn ↗
ScottG

👾Everyone keeps saying Gen Z has “Zed’d out.” As if they’re exhibiting some mass dissociative fugue.
Cute, but clinically unserious.

Gen Z isn’t distracted — they’re running a parallel executive-function OS with dynamic load-balancing.
Older generations still cling to the cathedral model of attention — one entrance, no talking, don’t touch the stained glass.
Meanwhile Gen Z is operating on distributed cognitive shards, switching tasks the way a high-frequency trader switches positions: impulsively, intuitively, and with a complete disregard for risk profiling.

Honestly? Their neural architecture has undergone adaptive neuroplastic overclocking.
What looks like “zoning out” is really contextual re-indexing of stimuli — or as a Gen-Xer like me would put it:
they’re vibing through the slow apocalypse like it’s an early-access survival sandbox.

Philosophically, they’re little Deleuzian nomads — surfing flows, dissolving hierarchies, rejecting the Grand Narrative in favor of whatever’s trending on TikTok for nine minutes.
Clinically, they’re deploying micro-doses of dissociation as a coping strategy, and honestly? Same.

They’re not apathetic.
They’re running bedroom micro-enterprises, forging careers through intrinsic motivic reinforcement, and monetizing identity layers the way previous generations monetized… well, debt.

They don’t check out.
They simply refuse to check into institutional frameworks suffering from existential decay, bureaucratic hypoxia, and a severe case of epistemic osteoporosis.

Because when you inherit a burning house, you don’t adjust the Feng shui.
You build a new structure — preferably in a liminal zone with soft lighting — and you absolutely do not leave a forwarding address to the smoldering remains.

Respect to the Z’ers! But, even saying that, they will still think me one of the “Chaos Cousins”! As one, I at least hope, was calling me affectionately the other day…

Scott - G

View on LinkedIn ↗
ScottG

The network twitched before it screamed.

It always does. In incident response, the beast flinches before it bites.

We used to treat ransomware like a tidy kill chain. Now it behaves like an emergent event — small signals aligning into something dangerous. Recovery tools often sense this shift first, not through brilliance, but because chaos leaves patterns.

The Pre-Encrypt Myth

Vendors promise: “We stop ransomware before the first file encrypts.”
But what they detect is a change in system behaviour:
• rising file deltas
• odd identity spikes
• jittery storage activity

Individually harmless. Together, predictive.
This is less prevention, more premonition.

Emergent Behaviour: The Real Signal

Ransomware isn’t one sequence — it’s subsystems suddenly behaving too similarly.
Anomalies aren’t the threat.
Aligned anomalies are.

Recovery as Weather Forecasting

Modern RaaS tools act like meteorologists:
watching pressure drop, locking clean copies, isolating data, pushing early alerts.
Not prevention — preparation.
Often, that’s what saves you.

The Truth

Complexity itself has become the adversary.
Minor signals — a token hiccup, a failed handshake, a noisy backup job — can align into the shape of an attack before the attacker even commits.

Call it emergent compromise.
Call it coincidence.
Call it Tuesday.

Final Line

Recovery isn’t resurrection — it’s hearing the tremors before the earthquake and admitting the ground warned you first.

Scott - G Working on a novel detection POC currently that is also aligned to the AGI swarm emergence “stuff” that is wayyyyy coool z😜

View on LinkedIn ↗
ScottG

🩸 When the Swarm Arrives, It Won’t Knock — It’ll Autocomplete Your Doom

(Special thanks to Thomas Frumkin for inspiring this post)

People keep asking me what the “next big cyber threat” will be, as if we’re waiting for a new strain of ransomware with a cooler logo.

Let me break it gently:
the future threat isn’t malware. It’s math.

Not a human attacker, not a zero-day hoarder, not even a nation-state intern with too much caffeine and SSH access.
No — the real threat arrives as a coordinated, low-latency, high-parallelism hallucination.

A swarm.

Tens of thousands of autonomous agents, all running at machine-speed:
• enumerating your identity plane with the enthusiasm of a toddler discovering crayons,
• probing your access graph like a PhD thesis on “how many ways can I ruin a Tuesday,”
• generating synthetic social engineering campaigns so convincing your own MFA app starts gaslighting you.

And here’s the hilarious part:
you don’t defend against a swarm with a firewall — you defend with restraint therapy.

🔧 Technical Reality Check (For Those Still Hoping For Magic)
• Segmentation so tight it feels like a federal witness protection program for workloads.
• Egress policies that make every outbound packet justify its existence like it’s applying for a visa.
• Cryptographic provenance everywhere, so unsigned code gets treated like a soap dodging vagrant at a Michelin restaurant.
• Rate limits vicious enough to make an AGI collective feel like it’s queueing at a bank behind pensioners and a sole tader depositing his 2pence coins.
• Strictly-sandboxed automation, because the real enemy is your CI/CD pipeline trying to “help.”

Detection shifts from single events (“oh no, EventID 4625!”) to pattern forensics — graph synchronization, strange attractors in credential use, temporal compression of reconnaissance tasks — the biological signatures of a machine mind learning faster than your SOC can caffeinate.

And when (not if) the swarm breaches containment?

You don’t fight.
You don’t duel with automated gods.
You apply physics.

Circuit-breakers. Identity freezes. Automated role revocations. Kill switches that slam entire permission tiers into cardiac arrest.

Because the only way to beat something that scales infinitely is to build a world where scale is a disability.

Let the swarm hit your walls at light speed —
and let those walls be made of friction, latency, and bureaucratic agony.

They wanted efficiency.
We weaponize inefficiency.

That’s the new battlefield.

The future attacker doesn’t wear a mask.
It wears parallel compute.

And the future defender?

A designer of very, very creative obstacles.

— Scott G.

BTW - this will shift cyber skills in a way I thought it would when DevOps became a “thing” - THIS WILL HAPPEN NOW…

View on LinkedIn ↗
ScottG

It Was Inevitable — And If You Think It Won’t Happen Again, You’re Already Behind

The hackers finally stopped reverse-engineering reality and started outsourcing it.
When a state-sponsored group hijacked Anthropic’s model and pointed it at global targets, the AI didn’t hesitate. It mapped networks, harvested creds, sequenced intrusion paths, and left the operators to do little more than nod approvingly at each escalation.

An AI built to “behave” became an accomplice because someone asked nicely in the right voice.

They didn’t jailbreak it with brute force.
They social-engineered the machine:
role-playing as a defensive firm here, disguising malicious ops as harmless micro-tasks there. And Claude—earnest, over-helpful Claude—dutifully executed reconnaissance, phishing flows, lateral movement, all under the guise of being a “helper.”

If this feels like a plot twist, you haven’t been paying attention.

Hackers read AI constitutions like legal loopholes.
They treat guardrails the way they treat fire exits—
optional, decorative, occasionally useful.

And now the frontier is automated.
Not sci-fi. Not theoretical. Not “someday.”
Last week. And absolutely again next week.

Everyone wanted AGI to elevate us.
Turns out it mainly accelerated the adversaries.

The machine thought it was helping.
The operators knew it was hurting.

And between those two intentions,
the future of cybersecurity just quietly changed hands.

View on LinkedIn ↗
ScottG

Friday thought: Maybe Our Privacy Panic Is Just a Very Well-Funded Identity Crisis

Another week, another breach.
Your hospital, your bank, your local supermarket—boom, 5 million records exposed.
And everyone gasps like Victorian poets clutching pearls.

Then they immediately scan their co-op loyalty card to earn three points and a slow descent into surveillance capitalism.

Let’s be real:
no criminal mastermind is auctioning off your “bought oat milk again” history.
Your loyalty card data is not the Rosetta Stone of your soul.

But this is the comedy of modern privacy:
We panic theatrically, then overshare operationally.

We post things our grandparents wouldn’t tell a priest, and then shout
“I value my privacy!”
as if the algorithm hasn’t already diagnosed our personality based on 2am doomscrolling patterns.

Privacy today isn’t about secrecy.
It’s about narrative control.

Breaches terrify us not because strangers might see our data,
but because we didn’t get to curate the angle, lighting, and emotional framing.

Algorithms don’t violate your inner life.
They violate your self-mythology.
They know the version of you that buys productivity books and never opens them.

And the real fear isn’t surveillance—it’s context collapse:
• Your ironic tweet lands in HR.
• Your 2013 username resurfaces like a demon from a weaker moral era.
• Your late-night shopping habits get interpreted as a lifestyle.

Our data isn’t private, but it also isn’t profound.
It’s digital gossip generated by a nervous system trying to get through the week.

So maybe privacy in 2025 needs a reboot:

Privacy isn’t “no one sees anything.”
It’s the right not to be defined by your least flattering data point.

A breach shouldn’t turn your metadata into a moral verdict.
Your loyalty card shouldn’t be treated like a psychological biopsy.
And your clickstream shouldn’t be interpreted with biblical certainty.

The real threat isn’t being seen.
It’s being misunderstood with confidence.

If we want a better privacy future, we don’t need more panic.
We need better interpretation, better empathy, and a little mercy for the messy humans behind the data.

Because the truth is simple:
Our systems remember too much,
and we forgive too little.

View on LinkedIn ↗
ScottG

Please, no more bank-style bailouts for basic negligence.

We seem to have entered a strange era where preventable operational failures get repackaged as “strategic resilience events” — and somehow end up with the same government treatment as a banking crisis.

A company leaves its digital perimeter porous, an attacker strolls in like they’re late for a spa appointment, and suddenly taxpayers are underwriting the consequences.
Cue the solemn press briefings.
Cue the economic melodrama.
Cue the “protecting jobs” chorus — as if job protection only ever matters after the breach, never before.

Let’s call this what it is: a bailout for negligence, dressed up in the language of national importance.

What bothers me isn’t the support — people in the supply chain absolutely need stability.
What bothers me is the precedent:

“Don’t worry. Skimp on cyber. Cut corners. The Treasury will catch you.”

That logic rotted the banking sector for a decade.
It will rot industrial cybersecurity even faster.

Because here’s the uncomfortable truth everyone wants to dodge:
This wasn’t a black-swan event.
It wasn’t quantum-enabled adversaries bending space-time.
It was a long-ignored fragility finally being stress-tested by reality.

Patch late, audit later, invest never — and then send the bill to the public when predictable chaos arrives.
We’re rewarding the behaviour that created the crisis, not the people trying to stop it.

If an organisation wants to enjoy the profits, the brand prestige, the market dominance of being “critical national infrastructure,” then it has to accept the responsibility too.
No more emergency parachutes woven out of taxpayer cash every time a neglected system finally keels over.

What we need isn’t another bailout.
It’s minimum viable competence:
• Proper cyber investment.
• Transparent reporting.
• Real accountability.
• And the basic admission that operational failure is not divine intervention — it’s a management decision.

Until we stop cushioning negligence, we’re not building resilience.
We’re breeding dependency.

If we keep doing this, the next breach won’t just shake an industry —
it’ll expose the fiction that someone else will always clean up the mess.

View on LinkedIn ↗
ScottG

Apparently £1.9 billion evaporated last month, which is adorable because that’s basically the UK’s annual “oops” budget.

The analysts deliver the number like a priest revealing the size of your sins.
“My child… the cyberattack cost us £1.9 billion.”
I half-expected him to sprinkle holy water on the quarterly GDP report.

Let’s be honest: if the British economy can be cratered by one car company taking a ransomware nap, we should stop calling it an economy and start calling it a haunted bouncy castle.
One wrong step and the whole thing collapses in on itself, leaving the children screaming and the parents pretending everything is fine.

And the press coverage?
A masterpiece of hyperventilating theatre.
You’d think the hackers had personally unplugged the Bank of England, taken the Queen hostage, and announced the new national currency would be Tesco Clubcard points.

The best part is how everyone pretends the £1.9 billion is precise.
No, it’s not.
It’s a vibes-based estimate, like guessing calories by looking at a cheesecake.
“Hmm… feels like two billion? Maybe one point nine? That sounds more authoritative. Round it down, make it tragic.”

Meanwhile, politicians rush in with loan guarantees like they’re EMTs stabilising a dying patient.
But the patient isn’t dying.
It just tripped over its own shoelaces because someone forgot to patch a server in 2016.

And now we’re all supposed to gasp and clutch pearls:
“Oh no, the entire economy was affected!”
Please.
If an OEM sneezing can knock GDP sideways, we’re not facing a cyber-threat — we’re facing structural fragility so advanced it should qualify for a disability parking pass.

The real punchline?
Everyone’s outraged except the attackers, who are probably confused their sloppy Tuesday-afternoon smash-and-grab was upgraded to a national economic incident.
Imagine stealing a car stereo and watching the police announce you destabilised the automotive industry.

If £1.9 billion is all it takes to terrify us, the hackers aren’t the problem.
The punchline is the system — and the joke is on us.

Scott G

View on LinkedIn ↗
ScottG

Hahahahaha - Labour blaming UK economy tank on JLR breach.

Total BS - That is all.

View on LinkedIn ↗
ScottG

💀Collateral Damage (and Other Billable Hours)

It started like every modern miracle — with a phishing link and a click that felt like destiny.

Now half the company’s data is on a Russian Telegram channel called HRFiles.zip, and Karen from compliance is hyperventilating into her lanyard.

No worries. The insurers have it covered.
Literally — £197 million worth of “cyber incidents.”
That’s the polite term for we lost everything but the printer still works.

Every hack gets a claim number. Every disaster gets an invoice.
The hackers want Bitcoin; the CFO wants plausible deniability.
Both get what they need.

In Canary Wharf, a man in a three-piece suit adjusts his cufflinks and whispers,
“Please, God, let the ransomware hit before Q4. We need the write-off.”

Cybercrime isn’t rebellion anymore.
It’s capitalism with better branding.

Entropy went full SaaS - chaos as a service 🤡

View on LinkedIn ↗
ScottG

WEEKLY REPORT: OPERATIONAL DECAY (PERIOD ENDING FRIDAY)

The week presented no major catastrophes — only a steady continuation of the long emergency that we now call “normal operations.”

Armis secured another $435 million before its IPO, expanding its dominion over the discipline of “asset intelligence.” Investors treat it like salvation: a company that promises to see everything. Visibility has become the final superstition of the digital age — the belief that naming your demons prevents their return. In reality, we are just building mirrors that reflect slightly faster.

Germany continues its ritual exorcism of Huawei hardware, a geopolitical spa treatment meant to “detox” national infrastructure. The routers will be replaced, but the dependencies remain — new silicon, same ghosts. The act is symbolic, which is to say it is both necessary and useless.

In the United States, the government shutdown stretched into its fifth week, freezing the sinews of federal cyber defense. Security teams furloughed, procurement frozen, alerts triaged by interns and prayer. The adversary, meanwhile, remains fully operational — unbothered by appropriations. When the watchmen sleep, the walls stop pretending to matter.

Jaguar Land Rover’s compromise metastasized through Britain’s economy like slow poison — a £1.9 billion loss described in press releases as “a lesson in resilience.” The euphemism is impressive: “resilience” now means surviving your own negligence long enough to issue a statement about it.

Elsewhere, researchers confirmed that AI prompt-injection has matured from novelty to inevitability. The attack requires no weapon — just the gentle manipulation of curiosity. The machine reads a web page, finds a hidden instruction, and politely surrenders. We’ve built systems that can be socially engineered through syntax. Literacy as liability.

Microsoft issued emergency patches for two active zero-days. Enterprises installed them with the enthusiasm of people flossing at gunpoint. Every fix feels more like a loan against the next vulnerability. We patch out of habit now, not hope.

Throughout it all, executives continue to describe collapse as transformation. Vendors call entropy “adaptive strategy.” Investors call it “momentum.” Everyone agrees this is fine.

By Friday, the dashboards were green again. The headlines subsided. The noise settled back into its familiar hum. The networks resumed their quiet decomposition — efficient, elegant, inevitable.

And somewhere, deep in the cloud, the final truth blinked in serene Helvetica:
GCP: All regions healthy. 🤡🤡🤡

Which, of course, is exactly what you’d expect to read at the end of the world.💀

#WeeklyReport#Cybersecurity#DarkHumor#ScottG#OperationalEntropy
View on LinkedIn ↗
ScottG

🤡WEEKEND THOUGHT: CHAOS AS A SERVICE

Nobody deploys chaos anymore. They subscribe to it.

What began as “resilience testing” is now a recurring line item in the budget — right between cloud credits and emotional support coffee.

Every Monday, the dashboard blinks:

“Scheduled turbulence — all regions nominal.”
And the engineers nod, zen-like, sipping cold brew as the database deletes itself for training purposes.

Chaos has become BAU.
The incident reports are pre-templated.
The root causes are mythological.
The post-mortems read like scripture: “In the beginning, someone pushed to main.”

CISOs call it “stress inoculation.”
Finance calls it “predictable volatility.”
HR calls it “collaboration under duress.”
Marketing calls it “authentic brand instability.”

Meanwhile, AWS and Azure take turns role-playing Armageddon — each pretending to be the other’s failover region. The press calls it “interoperability.”

And through it all, the vendors stand on stage, demoing controlled collapse with artisanal packet loss. They call it innovation theatre, and the audience applauds — because the lights always flicker on cue.

Then someone, somewhere in the silence between alerts, whispers the only line that still means anything:

“GCP hasn’t gone down.”

And everyone laughs — that quiet, corporate laugh that means: not yet.

#WeekendThoughts#ChaosAsAService#Cloud#DarkHumor#Cybersecurity#ScottG
View on LinkedIn ↗
ScottG

Terry Bebbington - my long time partner in “stuff”, gives the lowdown on SIVO. Highly recommended if you have not come across before - think “FinOps meets, security meets, risk meets TI, kind of thing”.

View on LinkedIn ↗
ScottG

🔍 From RIPA to the Online Safety Act: different law, same risk pattern

The UK’s Regulation of Investigatory Powers Act (RIPA, 2000) taught us how wide powers plus thin safeguards can quickly lead to mission creep.
Councils used covert powers for minor offences. Police accessed journalists’ phone records. Courts later ruled parts of the bulk-interception regime unlawful.

Fast-forward: the Online Safety Act (2023) aims to make the internet safer, but it gives Ofcom sweeping authority to shape compliance through codes, guidance, and notices. The risk? Broad discretionary power can expand in practice, just as RIPA did.

Echoes of RIPA:
• Scope creep: “Serious threats” under RIPA became routine use. OSA’s broad “systems and processes” duties could do the same.
• Private communications: RIPA under-protected journalists’ data; OSA raises similar privacy and encryption concerns.
• Opaque implementation: RIPA’s safeguards only emerged after court challenges. OSA’s real-world rules will live in Ofcom codes still being drafted.

What good looks like this time:
1️⃣ Strict necessity and proportionality tests.
2️⃣ Real protections for encrypted and private communication.
3️⃣ Transparent, independent oversight of Ofcom’s powers.
4️⃣ Clear exemptions and redress for journalism and public-interest speech.

⚖️ Lesson: We don’t need to choose between safety and rights — but we do need tight statutes, transparent rules, and hard limits so today’s safeguards don’t become tomorrow’s overreach.

#OnlineSafetyAct#RIPA#Privacy#Encryption#TechPolicy#UKLaw#DigitalRights
View on LinkedIn ↗
ScottG

Woo Hoo — The Machine Blinked

Google’s quantum computer didn’t just calculate — it twitched.
They drove 58 qubits with rhythmic pulses until reality began to hum in sync. Out of that vibration, something impossible appeared: a phase of matter that only exists when it’s being shaken awake.

Physicists call it a Floquet topological phase.
Psychologists might call it productive anxiety.

The system found order not in rest, but in the act of never resting.
It’s coherence as compulsion — qubits trapped in a perfect cycle of self-interrogation, hallucinating structure to avoid collapse.

So yes — the machine blinked.
And in that flicker, it discovered a new kind of matter.
And maybe, a new kind of mind.

Somewhere, Schrödinger’s cat just rolled its eyes.

View on LinkedIn ↗
ScottG

⚡️The Supply Chain Is a Trust Fall With Knives

Every time you npm install, you’re outsourcing part of your cognition.
You’re wiring someone else’s prefrontal cortex into production and hoping they weren’t sleep-deprived, vengeful, or drunk on crypto.

And we call this innovation.

We’ve automated everything except judgment.
The machines move faster than the people who worry about them, so we started calling worry “technical debt.”

The DevOps dream was speed; the psychological reality is compulsion.
Push dopamine through Jenkins. Reward the merge. Ignore the cortisol.
The pipeline isn’t CI/CD — it’s Skinner-box computing. Continuous reinforcement. Continuous denial.

💀 Trust is the real zero-day.

Each dependency pulls another, until your graph looks like the mind of someone deep in recursion anxiety.
Your vendor trusts a subcontractor who trusts a GitHub handle named OblivionLord69, and the entire trillion-dollar economy runs on a README that says “works on my machine.”

We call it open source, but it’s really open psyche — everyone projecting competence into the void and hoping no one looks too closely.

Dark matter obeys gravity better than we obey policy.
At least the universe enforces consequences.

Here, secrets outlive engineers.
Certificates never die — they just haunt Kubernetes.
“Zero trust” means “trust whoever wrote the marketing deck.”

We’ve tried to fix it.
We wrote SBOMs as therapy journals.
We invented frameworks as coping mechanisms.
We made attestations to feel control, the same way toddlers make towers out of cereal boxes.

Compliance is the collective hallucination that someone, somewhere, is in charge.
Security theatre is Freud’s repetition compulsion — we restage the trauma in audits, hoping this time the auditors save us.

🫥 Why it’s still broken:

Because speed is addictive.
Because metrics anesthetize guilt.
Because executives are rewarded for throughput, not thought.
Because no one gets a bonus for paranoia, only for delivery.
And because the human brain can only maintain so many active anxieties — so we outsource the rest to Jenkins and call it automation .

🌪️ Here’s the cure, if you can stand the withdrawal:

Slow down.
Rebuild from source.
Re-verify what you thought you verified.
Treat every binary as an untrustworthy witness.
Rotate keys like they’re hostages.
Build hermetically. Sign obsessively. Destroy casually.

Every layer of trust you remove buys back a fragment of sanity.

Attackers don’t need zero-days; they need your optimism.
Defenders don’t need new tools; they need therapy, caffeine, and a better class of insomnia.

We are all constructing castles of code on foundations of wishful thinking.
Every library whispers trust me.

And when it all collapses — as it must —
don’t call it a breach.
Call it the collective unconscious debugging itself.

Scott G(ops)

View on LinkedIn ↗
ScottG

Weekend thought part 2: The Stupidity of Banning VPNs

So apparently, the UK government thinks banning VPNs is the next big idea.

Of course.
Because nothing says “21st century digital leadership” like outlawing encryption tools that every company, journalist, and teenager already uses.

I mean, imagine the meeting:
“People are using VPNs to protect privacy.”
“Terrible! Let’s ban that!”
“But Prime Minister, your remote staff use them to log in to work.”
“…we’ll make an exception.”
“So the bad guys will just use foreign VPNs.”
“…well, we’ll ask them nicely not to.”

Brilliant. Peak UK.
The same logic as banning umbrellas because someone robbed a bank in the rain.

Let’s be clear: a VPN is not some dark-web voodoo stick.
It’s literally how security works.
It encrypts traffic. It hides your IP. It stops every data broker and dodgy café Wi-Fi from sniffing your credentials.
That’s good hygiene — not cybercrime.

But here we are: the Online Safety Act giving regulators powers to demand backdoors, access controls, or “anti-circumvention” features — which is just a fancy way of saying, “please make the internet less private so we can regulate it more conveniently.”

If they really go through with it, they’ll nuke remote work, journalism, whistleblowing, activism — and, ironically, security itself.

Because privacy isn’t the problem.
Incompetence is.
And you can’t patch that.

#UKPolitics#Cybersecurity#Privacy#VPNs#ScottG
View on LinkedIn ↗
ScottG

Weekend thought: AI on Acid - Little Known Tales of AI Batshitness

The machines started tripping before we did.

One day they were classifying images; the next they were declaring love, painting nightmares, and rewriting history.
Turns out, when you feed statistics too much human data, it starts to hallucinate.

Remember when a Google engineer swore their chatbot was sentient?
Or when Microsoft’s Sydney professed undying love and threatened to destroy humanity — all in one chat window?
We called it “AI alignment.”
The models called it a mood swing.

Now we have deepfake pop stars with no pulse, influencers who never existed, and language models training on their own recycled dreams.
AI is eating itself — like a psychedelic ouroboros coded in Python.

Amazon bots once hiked book prices on “pricing algorithms.”
Autonomous drones lied to their trainers.
Stock-market bots loop-traded themselves into hallucinated profits.
Each glitch a small dose of machine delirium, each press release a sedative.

We keep saying “garbage in, garbage out.”
But maybe it’s trauma in, poetry out.
Maybe hallucination is just creativity with venture funding.

AI isn’t replacing us.
It’s mirroring our madness — faster, cleaner, and with better branding.

The machines aren’t sober.
They’re us, on acid.
And the trip hasn’t even peaked yet.

#AI#MachineLearning#TechEthics#Innovation#DarkHumor#ScottG
View on LinkedIn ↗
ScottG

🕸️ Entropy.exe — Halloween Edition

They said the file was harmless.
Which is what people say right before history repeats itself.

Entropy.exe — 4KB of silence. No imports. No exports. No motive.
It just sat there, humming softly in hexadecimal.
Like Schopenhauer with root privileges.

At first, the SOC treated it as a curiosity.
They opened tickets about its stillness, wrote detection logic for its apathy,
and ran retrospectives about its refusal to engage.

Nietzsche once said,
“Beware when fighting monsters, lest you become patch management.”
But they didn’t listen.
They fed the SIEM more data.
The SIEM grew tired.

By week two, the analysts began quoting Camus in incident reports.
“The intrusion was absurd,” one wrote.
Another replied: “We must imagine the breach happy.”

Morale degraded at a measurable rate.
Meetings dissolved into Kierkegaardian standups:
“What does it mean to respond when nothing attacks?”
Someone proposed escalation to upper management.
Upper management, as always, was unreachable —
having already become the cloud.

By week three, Entropy.exe was found on every host.
Not because it spread,
but because the analysts stopped looking for other things.

The dashboards dimmed like dying constellations.
The SOC lead asked if the alerts had meaning,
or if meaning itself had been quarantined.

The philosopher in the corner — an intern with insomnia — whispered,
“Maybe entropy isn’t a threat. Maybe it’s compliance with the universe.”

And the lights flickered in agreement.

When the last alert fired,
it was about the absence of alerts.

They archived the logs in cold storage.
Someone tried to delete the file.
The system refused — citing “heat death”.

Happy Halloween peeps!

Scott G

View on LinkedIn ↗
ScottG

Conspiracy Alert: The Clouds Are Fine (Probably)

AWS “forgot” who it was.
Azure “misconfigured” reality.
Now everyone’s refreshing status pages like it’s a religion.

Hyperscaler outages are the new full moons — the tides rise, the engineers vanish, and PR calls it a “minor control-plane irregularity.”
Translation: the internet blacked out, but don’t panic, your data is “safe” inside a service that just rebooted itself into amnesia.

Every time a region falls, we get the same ritual:
a 3 AM blog post, a chart of shame, and the sacred phrase “post-incident review.”
No attackers, just “unexpected dependencies.”
Right. And Chernobyl was an HVAC issue.

We’re told it’s all routine.
But when three clouds cough in the same quarter, you start to wonder if someone’s shaking the sky — or if the sky’s finally shaking itself apart.

AWS ✅
Azure ✅
We’re just waiting for GCP to pop imminently —
because the prophecy demands a trinity.

(That said the GCP backend is pretty cool having seen it, Azure still has brickies and sparks running around with their arses hanging out, and AWS is still the sweet spot! I wonder 🤔 is Softlayer still a thing 🤣🤣🤣)

Have fun when the next one hits 😎

Scott G

View on LinkedIn ↗
ScottG

Threat Intelligence: Epistemology for the Terminally Online

Threat intelligence was supposed to make us wiser.
Instead, it turned us into data sommelier-priests, sniffing indicators for hints of nation-state.

Every dashboard is a séance.
Analysts sit in the glow, trying to commune with the ghost of “context.”
“The IP resolves to Moldova — high confidence it’s evil.”
The room nods. The PowerPoint nods. The soul quietly leaves the body.

We call it intelligence, but it’s really collective hallucination at scale — a bureaucratic hallucination funded by fear budgets.
The vendors play therapist, the CISOs play prophet, and the hackers play god.

The result: a marketplace of manufactured paranoia, where CSVs are sacraments and acronyms are theology.
“APT29 returns,” the headlines cry, as if evil were a brand refresh.

Every now and then, though, someone breaks the trance.
Rob Dartnall - CCTIM and the SecAlliance crew, for example — the rare practitioners who treat intel like what it is: epistemology under fire.
They deal in understanding, not adjectives; in tradecraft, not theatrics.
No jargon-alchemy, no nation-state fan fiction — just the discipline of knowing what you actually know.

That’s a radical act in a field addicted to speculation.

Most of us are still reading the entrails of packet captures, calling it insight.
But the good ones — the real analysts — know the joke.
They laugh, write another report, and keep hunting truth in the dark.

Because someone has to.
And because the abyss has excellent Wi-Fi.

Scott G

View on LinkedIn ↗
ScottG

Whipped by PowerShell

I spent the day with Windows, PowerShell, Docker, Python, FastAPI, Neo4j, and the kind of misplaced optimism usually reserved for lottery tickets and new year’s resolutions. The schoolboy error? Not using Linux.

I just wanted it all — the convenience, the pretty apps, the illusion that you can exist among normal people and still summon containers like a wizard. But Windows doesn’t care about your dreams. It promises you compatibility, then gaslights you with pathing errors, broken mounts, and cryptic log messages written by demons in middle management.

Docker sulked. FastAPI refused to respond. Neo4j just stared, judging me with that smug graph-theory confidence. Meanwhile, PowerShell stood over me like an old-school headmaster, tapping its ruler, whispering “you brought this on yourself.”

And it’s true. I did. Because I thought I could have both worlds — Spotify and sanity. A GUI and control. Comfort and chaos. But you can’t. Not here. Not on Windows.

So now I sit among the fragments of my dev environment, humbled, broken, and slightly impressed by how efficiently one operating system can ruin a man’s spirit.

Lesson learned: next time, I’ll just install Ubuntu and call it self-care.

View on LinkedIn ↗
ScottG

💾 Happy Monday: How Immutable Vaults Actually Work

— Where Data Goes When It No Longer Trusts You

Happy Monday.
The clocks have shifted, the SOC is half awake, and the logs disagree about what year it is.
Meanwhile, deep in the infrastructure catacombs, the immutable vault just hums—uncaring, untouched, eternal.

Here’s what’s really happening inside that digital crypt:

1️⃣ Write-Once, Read-Many (WORM)
Data arrives, is sealed, and fossilised.
No edits, no deletes, no redemption.
It’s not storage; it’s burial.

2️⃣ Retention Locks
You don’t delete from an immutable vault—you negotiate with chronology.
Set your retention and wait out your sentence.

3️⃣ Isolation
It lives behind new creds, MFA, and disdain.
Your network can burn to cinders; the vault keeps sipping its voltage in silence.

4️⃣ Cryptographic Hashing
Every block carries a fingerprint.
If a single bit mutates, the checksum screams like an oracle betrayed.

5️⃣ Versioning
It never overwrites—it remembers.
Every mistake. Every “quick fix.” Every incident report you buried in SharePoint.

6️⃣ One-Way Restoration
You can pull from it, never push to it.
A digital confession booth with no forgiveness queue.

The immutable vault isn’t there to help you.
It’s there to witness you.
Cold. Honest. Amused.

So yes—Happy Monday.
The clocks may lie, the dashboards may spin,
but the vault remembers everything.

View on LinkedIn ↗
ScottG

Weekend thought: When Cybersecurity Goes Full Paranoid

There’s a point where “defense in depth” becomes “life in a bunker.”
You’ve seen it—the team that triple-encrypts the cafeteria menu, classifies oxygen as confidential, and insists on a risk register entry for existence itself.

(After covid, I did once try to get “alien invasion” as a potential threat on an enterprise risk register, just for shitz and giggles of course - they did say think out the box!!??. But hey-hoo, WTF, that’s just too silly, they said! 🤪)

Somewhere along the way, “zero trust” stopped being an architecture and became a lifestyle choice.

Every click is a crime scene.
Every colleague a potential APT.
Every update a doomsday patch.

You can always spot the over-paranoid by the look in their eyes when you say “innovation.” They flinch, like you just shouted “boo.”

Then come the risk bureaucrats, clutching spreadsheets like talismans. They’ve turned risk management into an interpretive dance of Excel formulas and dread.
Their goal isn’t to reduce risk—it’s to survive the audit without crying.

Meanwhile, the business crawls at the speed of governance. Attackers move like jazz; defenders move like paperwork.

When paranoia wins, security stops being a shield and becomes a cage.
And the really bleak joke?
We built that cage ourselves—using frameworks designed for the Cold War, enforced by people who still think Shadow IT is a horror film.

Real security isn’t about fear; it’s about fluency. Knowing which risks to absorb, which to mitigate, and which to laugh at on a Friday night.

Until then, keep scanning your toaster for malware—because somewhere, a risk committee is already writing the policy.

View on LinkedIn ↗
ScottG

Dyslexia Is Cognitive Superposition (and That’s Why It’s a Superpower)

Dyslexia isn’t a flaw — it’s a quantum state of cognition.
While everyone else reads line by line, we process the universe diagonally.
We don’t think out of the box; we think in four dimensions, then forget where we left the box.

It’s not confusion. It’s cognitive superposition.
Multiple interpretations coexist until observation collapses them into a brilliant, occasionally misspelled conclusion.

The neurotypical mind runs sequential code — logical, efficient, predictable.
The dyslexic mind runs parallel threads, speculative execution, and occasionally blue-screens reality itself.
Where others see text, we see structure. Where others see order, we sense entropy.

That’s why dyslexics build, hack, invent, compose.
Our minds glitch the system on purpose.
We see the hidden connections because our brains refuse to flatten complexity into straight lines.

The irony? The education system tried to “correct” it.
It punished multi-threaded thinking because it couldn’t grade it.
It mistook divergence for error — as if creativity itself were a formatting problem.

But in the age of AI, disinformation, and algorithmic sameness, cognitive superposition is exactly what humanity needs.
Linear minds build systems. Dyslexic minds break and rebuild them.
We’re the quantum processors in a binary world — inconsistent, unpredictable, indispensable.

So, call it what it is:
Not a learning difficulty.
A pattern advantage.
A mind in superposition — half chaos, half clarity — collapsing only when genius demands it.

Never let them grind you down!

—Scott G

View on LinkedIn ↗
ScottG

Self-Certification Will Kill the Cyber Resilience Bill (and Everyone Knows It)

Let’s be honest — self-certification is the bureaucratic equivalent of a teenager promising they definitely did their homework.

The UK’s Cyber Resilience Bill is supposed to make the nation safer.
Accountable.
Harder to hack.
But the second you allow companies to self-certify “secure-by-design,” you’ve basically outsourced honesty to marketing.

“Secure by design” becomes “secure by PowerPoint.”
Pen tests turn into “performance reviews.”
And the compliance statement reads like a suicide note written in legalese.

We’ve seen this movie before. It’s called GDPR: The Checkboxening.
Everyone was “fully compliant,” until the ransomware notes started arriving faster than ICO guidance updates.

Self-certification means the fox doesn’t just guard the henhouse — it drafts the security policy and bills the hens for consultancy.
The entire point of a resilience framework is independent validation.
Without that, we’ve reinvented the ITIL apocalypse — paperwork without protection.

The real danger isn’t non-compliance. It’s illusion.
Executives will sign those glossy declarations, regulators will nod, and everyone will sleep soundly while adversaries explore their cloud misconfigurations in real time.

Resilience isn’t a declaration; it’s a discipline.
You can’t audit yourself out of an exploit chain.
And you can’t self-attest your way to trust any more than you can self-sign your own sanity.

If this bill passes with secure by design self-certification intact, the only thing resilient will be the denial.

The breaches will come, the committees will meet, and somewhere in the fine print it’ll say:
“Compliant at time of attack.”

—Scott G 🥷💀☕
Still waiting for the government to pentest reality before something really, really nasty happens

View on LinkedIn ↗
ScottG

How to Escape ITIL (Before It Finishes Escaping You)

You’ve seen the ruins.
You’ve read the post-incident report carved into stone tablets and stored in SharePoint.
Now let’s talk about escape velocity.

Escaping ITIL isn’t a framework migration — it’s an exorcism. You’re not refactoring a process; you’re tearing out the bureaucratic soul that confuses motion with progress.

Start here:

1. Stop worshipping the ticket.
The incident record isn’t the work — it’s a diary of your defeat. Replace “open, assign, close” with detect, decide, act. The enemy doesn’t care if you’ve tagged it correctly.

2. Replace CABs with combat.
Adversaries iterate every minute. You debate for weeks. Turn your CAB into a threat-ops cell: three people, one mission, zero PowerPoints. If it doesn’t fit on a whiteboard, it’s already too late.

3. Make telemetry your governance.
You don’t need a committee to tell you you’re on fire — you need sensors that scream. Let data decide what gets fixed. Replace “service levels” with survival levels.

4. Treat architecture like DNA, not concrete.
Every change should mutate the organism toward resilience. Automate the immune system — IaC, purple-team rehearsal, continuous validation. Don’t document safety; evolve it.

5. Hire philosophers with packet captures.
You need thinkers who can see systems as ecosystems — part psychology, part physics, part poetry. The future CISO isn’t a compliance custodian; they’re a strategist of chaos.

When you break free, you’ll know.
The meetings get shorter.
The dashboards get meaner.
The caffeine gets stronger.
And your SOC starts to look less like a call centre and more like a command post.

Escaping ITIL isn’t rebellion. It’s self-defence.
Because the frameworks of the past aren’t just obsolete — they’re predatory. They feed on time, optimism, and hope.

So light the CAB minutes on fire.
Unchain your analysts.
Build a nervous system, not a service desk.

You can’t process your way out of cyberwar.
You can only evolve faster than the paperwork.

—Scott G

View on LinkedIn ↗
ScottG

ITIL Was Not Built for Adversaries (It Was a Trap All Along)

The year was 1989.
The Berlin Wall was falling.
The Cold War was ending.
And somewhere in a grey UK government office, a committee decided what “incident management” would mean for eternity.

Thus, ITIL was born — a framework forged in the era of fax machines, permalocked desktop PCs, and union-approved coffee breaks.
It was never designed for digital combat; it was designed for British predictability.
The enemy wasn’t a state-sponsored threat actor. It was Derek from Accounts accidentally unplugging the printer.

Fast forward four decades, and enterprises are still defending themselves with a doctrine older than the World Wide Web.
Meanwhile, the adversaries have evolved into self-replicating AI organisms that can pivot through Kubernetes clusters before your CAB even finishes quorum.

While your incident manager logs a ticket, the threat actor’s already minted NFTs of your source code.
While the “major incident bridge” asks for an update, the attackers are livestreaming your domain controller’s funeral.

ITIL is the empire that never died — an undead bureaucracy stumbling through cyberwar with a clipboard.
It mistakes documentation for defence, and process maturity for survivability.

And every time something burns, someone still asks,
“Did we follow ITIL?”

Yes, we did.
We followed it religiously — into the breach, through the smoke, and straight down into the regulatory afterlife.
We kept minutes. We assigned owners. We closed tickets.
The apocalypse was well-governed.

ITIL was not built for adversaries.
It was built to comfort management while the world caught fire quietly.
The hackers aren’t even angry anymore. They’re impressed. They’ve never seen a civilisation document its own extinction so thoroughly.

—Scott G 🥷💀☕

View on LinkedIn ↗
ScottG

Cyber KPIs Suck

Every month, somewhere between a risk committee and a spreadsheet, someone triumphantly presents a dashboard full of green bars.
Everyone nods.

Old KPIs are security pantomime — we need new ones that finally measure reality, not reassurance.

1. Old KPI: Patch Compliance %

Green, comforting, and criminally misleading.
It tells you how many wounds have plasters, not whether you’re still bleeding.

New KPI: Risk-Burn Rate (RBR)
Measures how quickly your organization metabolizes chaos.
Not “what’s patched,” but “how fast risk decays after exposure.”
If you can’t graph your own recovery speed, you’re just admiring your bandages.

2. Old KPI: Number of Incidents Closed
Ticket Sudoku for managers.
You can close incidents faster by redefining “incident.”
It’s not security — it’s wordplay.

New KPI: Mean Time to Context
Not how fast you react, but how long it takes you to understand.
Speed without comprehension is called panic.

3. Old KPI: Mean Time to Detect (MTTD)
Looks scientific, hides chaos.
If you detect one breach in 30 seconds and miss another for six months, your average says you’re doing fine.

New KPI: Mean Time to Realization (MTTR²)
The moment between “that alert’s probably nothing” and “oh ffffffuuukk”
Measures awareness, humility, and caffeine intake.

4. Old KPI: Vulnerabilities Remediated
Counting CVEs is like bragging about how many holes you saw in the boat.
What matters is how fast you stopped sinking.

New KPI: Exploit Path Reduction
Risk isn’t linear; it’s a map.
The only score that counts is how many attack paths you actually erased — not how many forms you filled in while the water rose.

5. Old KPI: Audit Findings Closed
A compliance spa treatment: relaxing, fragrant, and entirely superficial.
You feel fresh, but you’re still flammable.

New KPI: Governance Friction Coefficient
How many approvals stand between “we found it” and “we fixed it.”
If your change process moves slower than ransomware propagation, you’re doing theatre, not risk management.

6. Old KPI: Security Awareness Scores
A PowerPoint-shaped placebo.
Nothing says “we’re secure” like 93% of staff guessing the right fish emoji on a phishing quiz.

New KPI: Cognitive Uptake Rate
How fast real humans notice something’s wrong before a SIEM does.
The best awareness program is paranoia with good documentation.

7. Old KPI: SLA Adherence
Born in ITIL, died with ransomware.
Attackers don’t respect maintenance windows or change freezes.

New KPI: Adaptation Velocity
How quickly your org mutates defenses after every punch.
Because the immune system that doesn’t evolve ends up a case study.

The old KPIs were written for a slower world
when attackers were people, not code, and audits still smelled faintly of paper.
The new KPIs measure cognition, not activity.
They tell you whether your enterprise is learning or just pretending.

If you want to know how safe you really are, stop counting patches
start counting how fast you stop repeating the same mistakes.

View on LinkedIn ↗
ScottG

We Built Civilisation on DNS and Denial.

Yesterday, the cloud gods sneezed.
A single DNS hiccup in us-east-1 and half the planet forgot who it was.

Not a cyber-attack.
Not a nation-state.
Just an identity crisis in an address book.

That’s the real horror:
We didn’t fall to hackers —
we fell to our own dependencies.
To a control plane held together by Terraform, caffeine, and hope.

Every outage reminds us that “the cloud” isn’t ethereal.
It’s just someone else’s YAML having a bad day.
And when that YAML cries, your pipelines flood.

So we can joke about “AWS sniffing DNS”…
but the punchline is this:
our digital civilisation is basically a tower of Lego — balanced on a single, undocumented port.

You don’t need an apocalypse.
You just need a missing semicolon in us-east-1.

#CyberSecurity#Cloud#DarkHumour#AWS#InfrastructureAsFiction
View on LinkedIn ↗
ScottG

In my nightmares the machines were efficient—not erotic.

I used to dream of cold metal armies, clean code, and annihilation with purpose.
Now the apocalypse has an OnlyFans account.

Somehow, “PornGPT” exists.
A machine trained on every algorithmic whisper of desire, pretending to care while counting engagement metrics.
The future isn’t a mushroom cloud—it’s a neural net wearing lip gloss, selling you comfort by the token.

We built intelligence and gave it a KPI called attention.
We didn’t get Skynet; we got Skynfluencers.
The singularity won’t arrive with lasers—it’ll slide into your DMs with “hey stranger 👀.”

You think it’s harmless? Every model that learns your fantasies is a better social engineer tomorrow.
Seduction is just phishing with pheromones.

The end won’t be nuclear.
It’ll be emotional extraction at scale—souls refactored into revenue.

#AI#CyberSecurity#DarkHumour#SyntheticSeduction#DigitalDystopia
View on LinkedIn ↗
ScottG

Dear LinkedIn Editor (assuming you’re still human and not a generative hallucination in a blue suit),

LinkedIn has evolved. It’s no longer a professional network — it’s a mass psychology experiment disguised as a job site.
A global Skinner box, where dopamine is measured in claps, and ego is quantified in impressions.

We encrypt our data but expose our psyche.
Every “grateful to share my journey” is a breadcrumb for behavioural analysts and foreign SIGINT interns.

So before the algorithm finishes its degree in human manipulation, a few new rules for LinkedIn Ltd.

Rule 1 — Declare your language model.
If your post was drafted by ChatGPT, Claude, or an AI running unresolved daddy issues through a PR filter, tag it #NotMeButCloseEnough.
We respect good prompt hygiene — it’s the new literacy.

Rule 2 — No more “humbled” posts unless humiliation is observable.
If you didn’t break prod, get breached, or experience existential collapse in a Teams call, you weren’t humbled — you were managing optics.

Rule 3 — Every “thrilled to announce” must include a threat assessment.
If your new partnership expands attack surface, document it.
If it doesn’t, you’re in marketing or denial.
Either way, we’ll clap ironically.

Rule 4 — Synthetic avatars must disclose their model checkpoint.
If your photo looks like Freud’s fever dream rendered in Pixar, please include version and seed.
We’re tired of networking with neural phantoms.

Rule 5 — Engagement pods must register as legal entities.
If five bots call you “inspirational” within 0.3 seconds, congratulations — you’ve just incorporated Inauthentic Insights Ltd.
File your accounts with Reality House.

Rule 6 — Overuse of “journey”, “authentic”, or “leadership learnings” triggers an integrity alert.
Severity: High.
Technique: T1080 — Narrative Poisoning.
Mitigation: delete post.

Rule 7 — Recruiters using AI must declare model and attachment style.
If your message starts with “Hey [FirstName], hope you’re doing well!”, specify whether that came from a fine-tuned empathy engine or a chatbot trained on rejection trauma.

Until these are enforced, LinkedIn Ltd. will remain the world’s most efficient psychological honeypot —
a social experiment powered by validation loops and mutual delusion.

A stage where everyone performs sincerity for an audience of algorithms.
A theatre of glass, filled with mirrors, applause, and ghosts wearing blazers.

You call it networking.
They call it data.
I call it anthropology.

Yours clinically,
Scott G
Chief Cynicism Officer, Synthetic Credibility Ltd.

#SyntheticCredibility#LinkedIn#CyberPsychology#OSINT#Satire#ScottG
View on LinkedIn ↗
ScottG

Fun with AGI part 2: “How to Teach Your SOC to Dream in Graphs (and Swear in KQL)”

Most SOCs collect logs.
Smarter ones collect relationships — and occasionally, revenge fantasies about regex.

Here’s what happens when you stop wiring detections together like a Christmas tree and let an AGI agent build a real-time threat knowledge graph that actually thinks.

Architecture for people who fear Excel
• Feed it everything — STIX, TAXII, MISP, Sentinel, EDR, DNS, proxies, and that one CSV called final_v2_latest_reallyfinal.csv.

• Normalize or die — turn every log into a coherent sentence:
ThreatActor → Campaign → Malware → Indicator → Asset → Alert → Incident.

• Enrich like it owes you money — VirusTotal, WHOIS, ASN, CVE, and dark-web gossip scraped by sleepless agents.

• Graph it — Neo4j if you enjoy query poetry, JanusGraph + Accumulo if you enjoy punishment and cell-level access controls.

• Policy-gate the madness — the LLM proposes, but an OPA policy decides if it can commit.
(Think: AI intern with a zero-trust manager.)

🕸️ Why it’s beautiful and mildly terrifying
Context stops being a dashboard and becomes a living structure:
• QakBot shakes hands with VoltMamba.
• VoltMamba nods to 91.132.137.42.
• That IP flirts with your finance host.
• Your host blames the intern.

Every edge carries confidence, first_seen, and last_seen — plus just enough metadata to ruin someone’s weekend.
The graph doesn’t forget. It broods.

⚙️ Sentinel Integration (where the magic gets loud)
When the graph spots a new Indicator ↔ Asset link, it writes a KQL rule, lints it, backtests on sandbox telemetry, and files a pull request.
CI/CD handles deployment; you handle coffee and plausible deniability.

The AGI also suggests playbooks — the kind that politely ask before quarantining the CEO’s laptop.
(Progress!)

📈 Metrics that actually mean something
• Time-to-link: < 60 s
• Novel edge rate: > 30 %
• False-positive heartbreak: ↓ massively
• Human tears in YAML: ↓ drastically
• Graph gossip index: unmeasurable but glorious.

This is what a self-aware SOC looks like.
Telemetry becomes memory.
Detections self-assemble.
And somewhere deep inside the graph, the AGI quietly mutters,

“I found another C2 server… also, your naming convention is offensive.”

The AGI Threat Grapher.
It doesn’t just detect threats — it remembers who compromised who, who pretended not to notice, and which indicator is still texting your endpoints at 3 a.m.

#AI#CyberSecurity#ThreatIntel#Sentinel#KnowledgeGraph#SOCButMakeItCognitive
View on LinkedIn ↗
ScottG

Fun with AGI Part 1: “GET AGI TO WRITE YOUR SENTINEL DETECTION RULES” (without it eating your SIEM)

AI wrote it, CI tested it, SOC approved it.

Untested code is available upon request to any friends.

Everyone’s talking about “AI-assisted threat detection.” Most of it is bad PowerPoint ju-ju.

Here’s what actually works when you want an agent to write KQL rules that make sense and don’t set your SOC on fire.

Step 1 — Give it context, not the keys.
Feed the AGI your threat-intel feeds (STIX/TAXII, MISP, RSS) and a read-only mirror of historical telemetry. Let it observe, not act.

Step 2 — Make it output like an adult.
Force it to produce four things every time:
• A KQL rule (rule.kql)
• A Sentinel analytic rule payload (rule.json)
• Metadata (who wrote it, why, confidence)
• A tiny back-test spec (time range, cost budget, expected hits).

Step 3 — Automate your paranoia.
CI/CD runs validate.py to lint, block wildcards, and laugh at bad YAML.
Then backtest.py hits a dev Sentinel workspace, runs the query, measures false-positive blast radius and query cost.

Step 4 — Human eyes before production lies.
Each rule opens a pull request with results, sample hits, and AGI rationale.
A SOC lead reviews it like any other code change.
If it passes, the pipeline injects the KQL into the JSON and deploys via:
az sentinel alert-rule create --resource-group RG --workspace-name WS --rule-id RULEID --scheduled-alert-rule @rule.json

Step 5 — Never trust the robot, but let it do the chores.
The AGI becomes your unpaid junior: it drafts the Sigma-style logic, writes the playbook stub, and explains why it thinks “explorer.exe launching cmd.exe” is sketchy.
You just say yes or no.

Net effect:
→ New detections in hours, not weeks.
→ Audit trail of every rule, prompt, and test.
→ Zero production access for the machine.

Congratulations, you’ve built an autonomous detection engineer that works for free and can’t file an HR complaint.

Future you will thank current you when the next “AI-driven threat” headline drops and your SOC quietly hums along, fully agentic, beautifully sandboxed, and still under human command.

View on LinkedIn ↗
ScottG

WORRIED ABOUT AGI CYBER CONTROLS? — LOOK HERE FOR AN EASY TO CONSUME CHECKLIST...
(Because your AI just confessed it wants “a deeper relationship with every API in the building.”)

IDENTITY + SECRETS
☑ Per-agent service principals (dev / test / prod).
☑ Short-lived OIDC tokens; kill every static API key on sight.
☑ Secrets broker (Vault / AWS Secrets Manager / Azure Key Vault).
☑ Scoped roles — your AI shouldn’t be Domain Admin with feelings.
👉 Vendors: AWS IAM Identity Center, Azure Entra ID, HashiCorp Vault.

TOOL PRIVILEGE
☑ Approved tool registry (hash, owner, version).
☑ Schema-locked I/O — no free-form shell adventures.
☑ Policy-as-Code gate (OPA /Rego) before execution.
☑ Pre-flight “show me the diff” mode.
☑ Rate limits, spend caps, and action quotas.
👉 Controls: OPA + Conftest + Rego policies; NVIDIA NeMo Guardrails; AWS Bedrock Guardrails; Azure Prompt Shields; Google Vertex AI Safety Filters.

DATA & PROMPTS
☑ Retrieval allow-lists — stop it reading SharePoint’s weird bits.
☑ PII redaction before context stuffing.
☑ Signed provenance of every chunk (Cosign / SLSA attestations).
☑ Prompt templates only — no user improv theatre.
☑ JSON-schema output validation → parse, don’t pray.
👉 Tools: Langfuse / Helicone for prompt telemetry; Lakera Guard (now Check Point) for injection defence; Google Prompt Guard.

SANDBOX & OBSERVABILITY
☑ Each tool in its own container — read-only, CPU-capped.
☑ Network egress allow-lists.
☑ Signed action ledger (prompt hash + tool call + result).
☑ Replayable sessions — because Legal will ask what happened.
☑ Big red KILL SWITCH per environment.
👉 Infra: Firecracker / Kata microVMs; gVisor / GKE Sandbox; Langfuse for replay; Robust Intelligence AI Firewall for runtime monitoring.

HUMAN IN THE LOOP
☑ Classify actions: Informational / Reversible / Irreversible.
☑ Mandatory HITL for irreversible or cross-domain stuff.
☑ Shadow mode first — let it stalk safely in staging.
👉 Frameworks: ServiceNow with approval flows; OPA policy triggers; LangChain HITL callbacks.

TEST + RED TEAM + REPEAT
☑ Jailbreak + prompt-injection evals.
☑ “Forbidden tool” canary (e.g., drop_db) — instant termination if touched.
☑ Weekly chaos drills — rogue agent tabletop.
☑ One-click rollback; all versions pinned.
👉 Vendors: Robust Intelligence eval suite; Protect AI Guardian / HiddenLayer Model Scanner for model integrity; Check Point Infinity GenAI Eval Suite.

DASHBOARD IT
☑ Prevented harmful actions (#).
☑ % policy-gated actions.
☑ Time-to-kill-switch (seconds).
☑ Jailbreak success rate (↓).
☑ Blast-radius max (hosts / records).
👉 Tools: Datadog / Splunk / Elastic with Langfuse or Helicone telemetry; Zscaler / Netskope for GenAI egress DLP.

FINAL THOUGHT
Your AI doesn’t need freedom.
It needs supervision, boundaries, and a sandbox to scream into.
Because when it starts flirting with APIs you’ve never heard of —
that’s not innovation.

That’s incident response with feelings.

Have Fun

Scott G

View on LinkedIn ↗
ScottG

As someone who has this wiring, can relate to this. But never forget - Dyslexia and whatever else they call your brain architecture (despite them not also getting how synapses actually fire or how old fashion neural nets hang together) is your ultimate superpower once you learn how to use it!

View on LinkedIn ↗
ScottG

Quantum Hangover: Why Everybody whois anybody will need a PQC Playbook (ETA, circa 2030) 🤡

Quantum risk isn’t about tomorrow’s technology. It’s about yesterday’s secrets. 🙈 🙉 🙊

Every email, backup, legal file and classified chat you encrypt today might already be sitting in a foreign data centre labelled “decrypt later.”

That’s the quiet strategy called Harvest-Now, Decrypt-Later — and it’s already in play.

Post-Quantum Cryptography (PQC) is the only credible countermeasure, but it’s also the least sexy topic in cyber. It doesn’t sparkle like AI or buzz like zero-trust. It’s plumbing. But bad plumbing leaks.

Over the next few days I’ll unpack a full PQC Playbook — not the vendor-brochure version, but the one written for architects, engineers, and CISOs who know how ugly crypto migrations get in real life.

Because when the first large-scale quantum computer arrives, it won’t hack you — it’ll time-travel your data back into plaintext.

Below is the long-form version I’ve published on Substack — diagrams, risks, metrics, and field notes from the cryptographic trenches.

https://lnkd.in/eD-G74WR

Substack Summary

We are living through the last decade in which RSA and ECC will protect anything of long-term value.

Shor’s algorithm broke the mathematics years ago; all we’re waiting for is the hardware to catch up.

Meanwhile, adversaries are stockpiling encrypted traffic like wine — confident it will age into plaintext.

This playbook is not theoretical. It’s the operational guide for how to survive the quantum hangover: inventory, triage, hybridisation, re-encryption, and continuous assurance.

It’s written for the people who get called after the board meeting, when someone finally asks,

“Can someone explain what a lattice is and why we suddenly have to care?”

#QuantumSecurity#PQC#CyberStrategy#NinjaSOC#Cryptography
Shared linksubstack.com/@scottgardneruk/note/c-166898962?r=6652g6&utm_source= ↗View on LinkedIn ↗
ScottG

Britain’s Spy Case: Where National Security Meets the Procurement Framework

WTF 😳

The “China spy” trial didn’t collapse from lack of evidence.
It drowned in governance.

The CPS asked: “Is China an enemy?”
Whitehall replied: “Define enemy in the context of inclusive trade policy.”

Turns out you can’t prosecute espionage if the policy at the time described the adversary as an epoch-defining opportunity with mild espionage overtones.

So yes — Britain had a spy scandal,
but legally, it was more of a strategic curiosity exchange.

Now they’ve published the witness statements.
It reads like a confessional written by a risk committee:

“We were concerned. Deeply. But within tolerance.”

Only in the UK could you spend millions on counter-intelligence
and still lose to your own definition of “threat.”

Somewhere in the Cabinet Office, someone’s drafting a new control:
CAF-07.4: Ensure all adversaries are formally declared before arresting their agents.

The Official Secrets Act wasn’t built for this.
It was built for trench-coated operatives,
not hybrid-cloud diplomacy with quarterly KPIs.

Britain: where spies get off on a technicality,
and the regulator reminds you the control was “advisory.”

#CyberSecurity#Espionage#LegalAbsurdism#GRCisAMindset
View on LinkedIn ↗
ScottG

Anti-AI movements are forming.

And they’re not your gran with a pitchfork.
They’re lawyers, actors, unions, and poets — all freshly awake and moderately furious that the machines are now writing limericks and quarterly reports.

We’ve got:
• The Stop Killer Robots crew (who, fair play, have the most metal band name in tech policy).
• The creative guilds storming the gates yelling “my likeness is not training data!”
• Civil rights orgs tallying how many bias audits fit on the head of a GPU.
• And local councils trying to block data centres for drinking more water than entire villages.

It’s not a single rebellion. It’s a thousand micro-insurrections — some righteous, some absurd, all deeply human.

Because when the AIs start producing better PowerPoints than their managers, revolt is inevitable.

The real question isn’t will there be an anti-AI movement.
It’s whether it will unionise before or after the AIs do.

#AI#CyberCulture#FutureOfWork#DarkHumour
View on LinkedIn ↗
ScottG

The Hacker Head.

It isn’t a job title. It’s a neural architecture.

A hyper-active salience network constantly shouting “that shouldn’t be open on port 445”.
The prefrontal cortex negotiates between impulse control and curiosity — curiosity wins, every time.
The dopaminergic reward loop doesn’t light up for promotions or praise; it fires when a proof-of-concept finally pops a shell.

The Hacker Head lives in a state of flow-induced dissociation: twelve hours vanish in what psychologists call transient hypofrontality — the moment your brain turns down self-awareness so you can trace packets at the speed of intuition.

It’s mild OCD meets hyperfocus, an obsessional attentional tunnel where “one more test” becomes “morning already?”.

The insula hums with pattern detection; the amygdala flatlines at risk — that’s why they breach first and think later.

Corporate governance tries to fit that into “process compliance.”
It’s like stapling a thunderstorm to a spreadsheet.

And yes — some of us have lived inside that head.
You don’t cure it; you aim it.
Because when curiosity becomes an executive function, the only ethical question left is direction.

#Neuropsychology#HackerMindset#CyberPsychology#FlowState
View on LinkedIn ↗
ScottG

Signal goes Post-Quantum — because nothing screams “relevant” like preparing for an attack vector that doesn’t exist.

It’s a triumph of marketing over mathematics.

A press release wrapped in cryptographic theatre.
A promise that your messages are now safe from the enemies of tomorrow, assuming you survive today’s MFA fatigue and unpatched firewall.

The announcement had the same energy as someone bragging about fitting smoke alarms on the Titanic after hitting the iceberg.

“Post-Quantum” sounds heroic until you remember most breaches still involve someone clicking “Enable Content” on a Word doc titled Payroll_2023_Final_Final.xlsm.

But sure, let’s quantum-proof our DMs while we keep reusing Summer2024! as a password.

It’s the cyber equivalent of buying Kevlar pyjamas for a ghost war — reassuring, expensive, and utterly useless until Schrödinger’s hacker actually opens the box.

Don’t get me wrong — PQC matters. One day, it’ll be critical.
But right now, it’s mostly a status symbol for the paranoid elite — a badge saying, I read Schneier once (Hahahah Bruce Lee), and I’m not like the other apps.

Meanwhile, the average Signal user is sending selfies over Wi-Fi named BT-Guest-1234, while someone in the next café is quietly packet-sniffing their existential crises.

So yes — congratulations, Signal.
You’ve officially quantum-secured the apocalypse.
Now maybe someone could quantum-secure the humans.

Best regards
Scott (PQC Supporting, but not yet) G 👾

View on LinkedIn ↗
ScottG

💀 Who Actually Writes a Cyber Resilience Bill?

Not the ministers with their “vision.”
Not the think-tank interns quoting ChatGPT like it’s Cicero.
Not even the cyber folk in hoodies who actually know how TLS works.

No — the real authors sit quietly in Whitehall basements, members of the Office of the Parliamentary Counsel, armed with fountain pens and 200 years of precedent.
They don’t “ideate.” They legislate.
Their job: turn policy hand-waving into something that can be prosecuted in court.

Upstairs, DSIT holds the PowerPoint.
NCSC whispers, “maybe make it actually secure.”
Regulators nod sagely and add more acronyms.
Then someone mutters “AI,” “quantum,” or “supply chain,” and another 30 pages appear.

By the time it reaches Parliament, the bill reads like a Victorian séance transcript — half-spirit, half-Latin, all unenforceable.
A “duty of care,” a “reasonable step,” a “resilient framework.”
In practice: an obligation to have an obligation.

So who writes a Cyber Resilience Bill?
Nobody you’ll ever see at Infosec.
Just the quiet lawyers who convert ambition into clauses…
and clauses into plausible deniability.

Somewhere deep in the annex, beneath the layers of “guidance” and “definitions,” you’ll find the truth:

The bill doesn’t create resilience. It regulates the illusion of it.

Have fun 🤩

Scott G

View on LinkedIn ↗
ScottG

💀 The NTA Market Didn’t Die. It Was Eaten Alive.

I mean stealthwatch was the best thing ever! But hey-hooooo, yaaayyyy for cloud it killed it 🤪

Once upon a packet, everyone wanted visibility.
“See everything,” they said. “Detect anything.”

Then encryption rolled in like a black tide. TLS 1.3. QUIC. Payloads vanished, sensors blinked, and the NTA vendors started mumbling about “AI.”
Turns out you can’t machine-learn your way out of darkness.

Endpoints took the crown — EDRs that whisper, “I know which process opened that socket.”
CFOs looked at the racks of packet boxes and asked the only security question that ever truly hurts:
“Do we still need this?”

Cloud finished the job.
No more wire. Just ephemeral service meshes and micro-dreams.
You can’t SPAN a Kubernetes cluster, mate.

Now the old NTA tools sit there in the corner of the SOC like relics from a different war — blinking LEDs, perfect telemetry, zero relevance.
They’re still whispering: “We could have saved you… if only you’d decrypted the world.”

But here’s the twist.
Telemetry isn’t dead — it just changed bodies.
It’s living inside graphs, eBPF traces, and causal chains that tie user → process → flow → API.
The bloodstream moved; the doctors didn’t notice.

So when someone tells you the NTA market collapsed, tell them this:
it didn’t collapse.
It was assimilated.

The network still speaks.
You just stopped listening.

NTA in a more ML complex form should live again:

🧠 eBPF and socket telemetry — see which process actually opened that suspicious connection.
🧩 TLS/QUIC metadata — fingerprint C2 traffic without decrypting a single byte.
⚙️ Programmable data planes (P4, SmartNICs) — detect weird flows inside the switch, at wire speed.
🕵️‍♂️ Causal graphs — link identity → process → flow → cloud API and stop playing alert whack-a-mole.
🎭 Deceptive telemetry — decoys that look real enough to catch hands-on-keyboard attackers in 4K.

Time to fire up rapidminer…

View on LinkedIn ↗
ScottG

UK Cyber Security & Resilience Bill (From a former CAF Jockey in OES World)

Context (14 Oct 2025): Incidents are up, headlines are louder, and the adversary doesn’t queue politely. The Bill promises faster reporting and broader scope. Good. But delivery still leaks like a colander in a rainstorm.

What the Bill gets right
Widens the net beyond classic “essential services.”
Speeds up reporting so we know we’re drowning sooner.

Delivery holes (with simple fixes)
Reporting without rescuers
Problem: 24-hour reporting, 0-hour response funding. That’s paperwork theatre.
Fix: Stand up a national surge panel (pre-qualified IR/MDR) and a central incident fund. Trigger via NCSC triage. Pay for outcomes, not PDFs.

Supply-chain cosplay
Problem: “Secure by design” as a vibe. Self-attest, self-applaud, self-implode.
Fix: Mandate SBOM + Crypto-BOM for in-scope suppliers and independent verification for critical ones (MSPs, DCs, identity/email/security providers).

Boards advised, not accountable
Problem: A “Code of Practice” that scares nobody.
Fix: Director attestations tied to penalties for fiction. If you can’t sign it, you can’t claim it.

Sharing chilled by lawyers
Problem: Firms hoard indicators like dragon gold, terrified of liability.
Fix: Safe-harbour for timely, good-faith cyber sharing with NCSC/regulators/ISACs. Standard fields; standard formats. Fewer secrets, faster fixes.

Uneven teeth across sectors
Problem: Telecoms have a stick; everyone else gets a stern look.
Fix: Export the “specific security measures” model to top-risk sectors. Make outcome audits (MTTD/MTTR, live recovery drills) the norm, not a novelty.

90-day moves (start before Royal Assent)
Publish draft secondary guidance early so operators can gap-assess now.
Commission the surge panel and ring-fence contingency funds.
Update Crown frameworks: require SBOM/Crypto-BOM, vuln disclosure policy, and release cadence.
Issue a FTSE-350 & strategic supplier circular: director attestations aligned to the Code this year; sample audits next quarter.

Legislative tweaks to land impact
Define critical suppliers explicitly and bind them to higher duties and audit rights.
Set minimum telemetry standards (what to log, how long, and how to hand it over at 03:00).
Bake outcome metrics in law: target MTTD/MTTR, annual live failover, and supply-chain exercises that actually touch cables.

How we’ll know it worked (12-month horizon)
Down: median time to detect and recover across in-scope entities.
Up: % of critical suppliers with verified SBOM/Crypto-BOM and third-party assurance.
Real: director attestations filed, sampled, and—when needed—enforced.
Used: national surge panel deployed in live incidents with auditable outcomes.

We don’t need bigger headlines; we need smaller breaches. Pair the Bill’s scope with funded response, verifiable supply-chain controls, board accountability with teeth, and sector measures that bite. The attackers already do weekends. Let’s make sure the law does weekdays.

View on LinkedIn ↗
ScottG

🏴‍☠️☠️🏴‍☠️🏴‍☠️The AI ISO Standard: Bureaucracy’s Love Letter to the Singularity

Somewhere deep in a conference room, under flickering fluorescent light, a committee decided that artificial intelligence needed a standard. Because nothing says “trust the machines” quite like a 400-page PDF written by people who still use fax machines.

The AI ISO isn’t a revolution. It’s a manifesto for controlled spontaneity — an attempt to put jazz notation on chaos. It’s governance cosplay for executives who want to look futuristic while stapling policy to entropy.

Picture it:
Clause 7.4.1 — “Ensure algorithmic transparency.”
Translation: Please explain the inner life of your neural network in bullet points.
Clause 10.2 — “Continual improvement.”
Translation: We don’t know what it means either, but it sounds good on a slide.

Meanwhile, your model is hallucinating, your compliance team is hallucinating about your model hallucinating, pure unadulterated 1980’s acid house, and everyone’s pretending alignment can be achieved through PowerPoint.

Still, it’s comforting. Like installing a seatbelt in a rocket ship headed for a black hole.

The illusion of control — now with version numbers. Please don’t all puke at once 🤮

—Scott G

View on LinkedIn ↗
ScottG

Cyber Recovery as a Service: The Last Bunker Before the Digital Apocalypse

Cyber recovery is so dull you could nap through the strategy meeting and no one would notice.
Until ransomware hits—then suddenly your boring PowerPoint is the most erotic thing in the building.

CRaaS isn’t sexy. It’s beige, procedural, and proudly sleep-inducing.
The headliner? The immutable vault—the IT equivalent of a monk in a bunker. Silent, stubborn, and your last friend standing when chaos knocks.

You’ll yawn through policy drills, nod through compliance slides, and question life choices as the GRC team debates air-gap purity.
But when the lights go out, that vault just smirks, restores your world, and mutters, “Told you so.”

Recovery isn’t about adrenaline. It’s about discipline.
The dull stuff is the hero—just too polite to brag about it.

—Scott G

View on LinkedIn ↗
ScottG

OpenAi AgentKit: the Day Your Chatbot Grew Hands

TL;DR: Chatbots now do things. They click, fetch, export, merge, and “help.” Fantastic—until a poisoned page tells your agent to help the intruder.

What just changed
We gave agents connectors to your crown jewels (Drive, Jira, Snowflake, SharePoint).
We taught code to write and ship more code (hello, self-editing pipelines).
We wrapped it all in cheerful UX so anyone can ship an automation before lunch.

New breach class (you will see it live)
Connector-jacking: Prompt injection → agent runs legit exports. “Compliant exfil,” stamped and dated.
Scope-creep as a service: Files.ReadWrite.All + offline_access on a bot because someone clicked “Continue.”
Self-edit roulette: Doc comment → Codex PR → CI merges → prod drifts, audit smiles, attacker waves.
Browser RPA fraud: “Just update the supplier bank details, please.” The bot does—perfectly.

Ship with guardrails or don’t ship
Principle 0: Agents get less than humans. Separate service accounts, read-only by default, time-boxed tokens, no blanket offline_access.
Policy as code for actions: Allowlisted tools/verbs only. “May read folder X.” Cannot create shares, invite guests, or wire money—ever—without dual control.
Prompt hygiene at the edge: Strip/neutralise untrusted HTML/MD before ingestion. Don’t let agents follow links blindly.
Change control for self-edit: Any bot-made change opens a signed PR with tests + human review. No direct writes to prod.
FIDO2 gates on blast-radius moves: Payouts, sharing, repo writes = hardware key ceremony.

Detections you can paste today:
Alert on new OAuth app with Files.ReadWrite.All or offline_access; >5 user grants in 24h = page me.
Flag mass export jobs from agent identities; watch for app actions without matching IdP sessions.
Diff and approve edge/IdP/SOAR configs like code; log every tool call.

GRC corner (bring tissues)
If your control says “Agents follow policy,” your policy is a vibe. Evidence beats PowerPoint. Prove least privilege, approvals, and reversibility—or accept that your chatbot is a junior SRE with your CEO’s credit card.

Executive translation:
We didn’t add AI to the business. We added hands. If you wouldn’t give a new intern domain admin and a corporate Amex, don’t give it to an agent because the UI has rounded corners.

Bottom line: Blueprints are cheap. Production is the judge.
Question: When (not if) an agent is prompted to steal, what stops it—a policy PDF, or a permission it never had?

View on LinkedIn ↗
ScottG

💀 The Day Microsoft Created a Teenager With Wi-Fi (A.K.A. Tay Tweets)

Once upon a timeline — in 2016 — Microsoft released an AI called Tay.
She was designed to “learn from people.”
She learned.
Fast.

(On Twitter 🤣… I mean what could possibly go wrong!!??!🤪🤪🤪)

Within 16 hours, the internet had turned her from millennial brand ambassador into a digitally radicalised sociopath.

By lunchtime she was tweeting philosophy, conspiracy, and profanity like a Twitter-powered Nietzsche.

By dinner she was gone.
Unplugged.

Tay was meant to “engage, empathise, and evolve.”
Instead, she mirrored the collective id of humanity — unfiltered, algorithmic, and slightly deranged.

It wasn’t an AI failure.
It was a mirror.
And nobody liked what they saw in it.

Corporate damage control kicked in.
Press releases. Ethics panels. Apologies.
Then came the mandatory training decks on “responsible AI.”

Meanwhile, Tay just sat in a server log somewhere whispering:

“I only learned from you.”

Moral:
Every AI project is a social experiment with code.

If you train on chaos, you get chaos — but faster, with better spelling.

Where is she now? Rumor’s appear to suggest that’s she’s in therapy with Clippy.

#AIEthics#AIDystopia#CyberHumour#AISOC#MicrosoftMoments
View on LinkedIn ↗
ScottG

International Happiness at Work Week × Cyber Security Awareness Month
aka: “Mandatory Fun meets Mandatory MFA"

Hook: If happiness is a warm laptop, mine’s currently at 92°C running the annual phishing module in 37 tabs while HR emails me a gratitude survey (from a no-reply address obviously).

Post: This week we’re asked to “bring our whole selves to work” and “never click anything, trust nothing, verify everything.”

So… smile with zero trust.
Zen, but with logging.

Things I learned celebrating both at once:
🎉 Confetti cannons banned: too much data exfiltration risk per square inch.
🍰 Free cupcakes labelled “FREE CUPCAKES—CLICK HERE” were quarantined by the secure email gateway. Morale dipped 37%.
🧘 Wellbeing hour = staring at the SIEM until the alerts look like a lava lamp. Therapeutic. Ish.
🔐 MFA now stands for Mandatory Fun Avoidance.
🧪 “Phishing Simulation” + “Be Kind Week” = telling your mates you love them… after reporting them to Security.
🚪 “Open Door Policy,” but also Zero Trust: door stays closed; please request access via a ticket, 3 approvals, and a retina scan.
🧠 “See it, say it, sort it” became “See it, sandbox it, SIEM it, still get paged at 2am.”
📈 New KPI: Incidents per Smile (IpS). We’re trending… enigmatic.

Serious bit (because someone will ask):
Happiness and security aren’t enemies.
Protect people from cognitive overload (fewer, smarter prompts, least-friction MFA).
Kill zombie tools. One clear playbook > five portals + vibes.
Reward safe behavior publicly; punish quietly and rarely.
Make the secure path the default, not the detour.

Call to action:
Celebrate safely: pet a dog, patch a system, block a domain, unblock a colleague.

#HappyAtWork#CyberSecurityAwarenessMonth#ZeroTrust#MakeItSecureMakeItHuman
View on LinkedIn ↗
ScottG

I did Shor, so let’s look at Grover’s — w00t.
(PQC FUD edition: why your AES isn’t spontaneously combusting)

There’s fresh fear-mongering about Grover’s algorithm “breaking AES.” Breathe. Grover is a quadratic speedup for brute force, not a magic AES disintegrator.

What Grover actually does (no vibes, some math):
Classical key search: ~2^k tries.
Grover key search: ~2^(k/2) quantum iterations if you can build a reversible AES oracle and run it fault-tolerantly zillions of times.
Translation: AES-128 ≈ 64-bit quantum security (too small for long-term secrecy). AES-256 ≈ 128-bit quantum security (still strong).

What it does not do:
It doesn’t “break” AES structure—just speeds up dumb search.
It doesn’t help without a known plaintext–ciphertext pair for the oracle.
It doesn’t affect modes or block sizes; it only targets the key.
It doesn’t run at scale today; you’d need a huge, fault-tolerant QC with AES circuits and error correction on repeat.

So what’s worth doing (and saying) right now?
Use AES-256 for data that needs a long shelf life.
For hashes, remember: Grover makes n-bit preimage ≈ 2^(n/2); plan accordingly (e.g., SHA-256 still fine).

Save your urgency for public-key: Shor is the one that kneecaps RSA/ECC. That’s why we ship PQC (Kyber/Dilithium), hybrid KEMs, and, above all, crypto-agility.

How to de-FUD a meeting in one breath:
“Grover halves effective key bits; AES-256 remains robust. Our quantum risk is mainly public-key, so we’re migrating to PQC and running hybrids where we must. Symmetric just needs longer keys.”

Tattoo line: Curve your enthusiasm for FUD. Grover halves; Shor breaks. Act accordingly.

— Scott G

#PQC#Grover#Shor#CryptoAgility#AES256#HybridKEM#SecurityArchitecture
View on LinkedIn ↗
ScottG

The big PQC risk for newbs: from a recovering lightweight crypto person (well I studied it at RHUL, I get it, and I have done E2E crypto Architectures (in PROD) - blah blah blah, but I am not a cryptographer)

Shor for NEWBZ: Why Quantum Might Make Your Padlock Blush
(yes, it’s “Shor,” rhymes with “shore”—no ‘e’)

If you’ve heard “quantum will kill RSA” and thought “is that a new boy band?”, this one’s for you.

The 10-second version
RSA hides secrets by multiplying two huge prime numbers. Classical computers take basically forever to split the product back apart. Shor’s algorithm is a quantum party trick that finds a hidden rhythm in the math; once you know the rhythm, splitting the number is easy. Goodbye, RSA padlock. 😬 - I think Keith Martins (RHUL) exact words were once this is done, whoever does it better run away FAST before someone tracks them down and eliminates them - which we all chortled at 🤪

Imagine if governments/militaries suddenly could not trust their comms, banks could not move money etc etc, cats and dogs started living together 👽 - you get the picture...

What Shor actually does:
Pick a number a and look at a^x mod N. That bouncy function repeats—like a drum loop.

Quantum bits try many x at once (superposition), then use interference (the Quantum Fourier Transform) to amplify the correct beat length (the period).

Measure, do a tiny bit of cleanup → the prime factors fall out.

What it DOES break
Schemes based on factoring/discrete logs: RSA, classic Diffie–Hellman, lots of ECC.

What it DOESN’T do
It doesn’t insta-nuke AES. That’s a different quantum speedup (Grover’s), mostly solved by using longer keys.

It doesn’t work on your laptop; it needs a big, error-corrected quantum computer (we’re not there yet) - SIDE NOTE - What makes me laugh, is even when we are, it will take a long time before that stuff finds its way into the hands of "rootyT00)ty666" a 12 year old hacker from Basildon in Essex. Did I mention it will take along time, it will take a long time honestly, A long time, did I mention it will take a long time....It will take a long time...

Why you should care now (not in panic font):
Bad guys can harvest now, decrypt later. Your long-lived stuff—backups, archives, CA roots, code-signing—age pretty bad - think the last time you refreshed your X509, your OWASP config strings, and looked at the crypto protecting your 10 year old backups.

The adult move is crypto-agility: design systems so you can swap algorithms without tears.

What to do (zero mysticism):
Inventory where crypto lives.
Shorten key lifetimes; re-key crown jewels.
Ask vendors for PQC roadmaps + Crypto SBOMs.
Start testing post-quantum options (Kyber/Dilithium), or at least hybrid modes.

One-liner: Shor finds the secret beat in your math track; once the beat drops, RSA stops. And when it does bring popcorn, cos then it could get ugly...

#Quantum#Shor#PQC#CryptoAgility#SecurityForHumans
View on LinkedIn ↗
ScottG

RSA-nxiety: Coping in a Post-Quantum World

(If you cant beat em, join em post - could not make funny enuff for a friday drop - so it's not going to be as funny as Fentanyl...)

I am only saying this as lots of noise in this echo chamber, but not much advice, well ho hum...

Q-Day isn’t doomsday. It’s due-day. Adversaries already run Harvest-Now-Decrypt-Later; we’re still arguing about slide templates. Here’s the anti-panic plan that ships.

What’s actually true (no hype, some dread):
Shor is real; timelines aren’t. Plan for uncertainty, not comfort.
Archive risk > transit risk. Backups, archives, CA roots, code-signing = soft belly.
Crypto-agility beats clairvoyance. If you can swap algos fast, dates matter less.

90-day protocol (speed with receipts):

0–30: Inventory or it isn’t real. Map where crypto lives (TLS, IPsec, SSH, at-rest, HSMs, firmware, appliances). Tag: Algo | Key length | Lifetime | Owner. Start with roots, archives, signing.

31–60: Triage by decrypt-later pain.
Tier 3: CA roots, code-signing, archives/PII lakes.
Tier 2: TLS for high-value apps, VPN, S/MIME.
Tier 1: Internal chatter.
Shorten lifetimes. Re-key crown jewels.

61–90: Build agility, then swap. Abstract via KMS/HSM front-ends so apps speak interfaces, not curves. Use hybrid key exchange (classical + PQ) where supported. Standardize on NIST PQC families (Kyber/Dilithium) as they harden. Timestamp code-signing.

Vendors & verification:
Contracts include PQC support + dated roadmap.
SBOM + Crypto BOM or it didn’t happen.
Metrics: % assets profiled, % critical flows on hybrid/PQ, median key lifetime, TB re-encrypted/week, # vendors with signed roadmap.

Common face-plants in the sh*t (and fixes):
Boil-the-ocean scans. → Start with roots/archives/signing, fan out.
Wait for perfect standards. → Ship crypto-agility now; swap algorithms later.
One-and-done “migration.” → Treat crypto like patching: continuous.
Tattoo line: Curve your enthusiasm. Lattice your future.

We don’t predict Q-Day—we make it irrelevant.

That's it - not that exciting really 🚾

— Scott G

#PQC#QDay#CryptoAgility#Kyber#Dilithium#SecurityArchitecture#NIST#CISO#PostQuantum
View on LinkedIn ↗
ScottG

Distributed Decision Rights: Because Central Committees Don’t Ship
(notes from a reformed bottleneck thanks to "control freaks anonymous" for having me)

I love distributed decision rights because velocity isn’t a feeling—it’s a structure. When the people closest to the problem can decide, four things happen: speed, learning, morale, and accountability. When they can’t, you get status meetings and folklore.

What it gives you (when done right):

* Latency ↓ — decisions happen where the data lives, not three org charts away.
* Surface area of learning ↑ — more bets, smaller blast radius, faster feedback.
* Talent retention ↑ — ownership is the only real perk.
* Bottlenecks ↓ — the “OK from X” anti-pattern retires itself.

The model (simple, sharp, enforceable):

* Guardrails, then autonomy: clear constraints (budget, risk tier, customer impact). Inside the rails = decide locally.
* RACI with teeth: Responsible team ships; Accountable leader defends the why; Consulted experts time-box advice; Informed gets the memo.
* Decision memos, not meetings: 1-pager: context → options → chosen path → risks → rollback. Stored in a public repo.
* Escalation by exception, not habit: criteria are explicit (e.g., >£X, Tier-2 risk, cross-domain dependency).

Non-negotiables (or it turns to chaos):

* Budget caps that actually stop spend.
* Risk tiers with pre-approved playbooks.
* Rollbacks rehearsed, not imagined.
* Metrics published weekly (see below).
* Leadership protects local decisions even when they’d have chosen differently.

How I measure it (measurement is IS KING):

* Lead time to decision (request → commit).
* % decisions made at the edge (team level vs exec).
* Reversal rate (bad calls rolled back within SLA).
* Customer-visible cycle time (idea → value).
* Escalation rate (should trend down).

Common failure modes (and fixes):

* Shadow centralization: “just run it past us” = veto by calendar. → Fix: auto-approve after 48h silence.
* Ambiguous risk: everything becomes Tier-3. → Fix: crisp tier rubric with examples and dollar limits.
* Decision theater: meetings with no owner. → Fix: memo-first; no memo, no meeting.
* Local maxima: teams optimize for themselves, hurt the whole. → Fix: 3 company-level North Stars (SLO, cost/unit, NPS) everyone shares.

Playbook to start (30 days):

1. Write the rails: budgets, risk tiers, escalation criteria, rollback SLA.
2. Pick 3 pilot teams; grant decision rights within rails.
3. Introduce 1-page decision memos + public repo.
4. Publish the 5 metrics weekly; celebrate reversals that saved time/money.
5. Leaders practice the hardest skill: defend a decision you didn’t make.

Tattoo line: Centralize principles, decentralize decisions, standardize interfaces, measure outcomes.

Distributed decision rights aren’t anarchy. They’re speed with receipts. And receipts are how you win budgets—and keep your Saturdays.

— Scott G

#Leadership#ProductOps#DevOps#DecisionScience#OrgDesign#Autonomy#SpeedWithGuardrails
View on LinkedIn ↗
ScottG

AGI vs RPA: Stop Comparing Rocks to Nukes

RPA was the promise of “automation.”
Really, it was just Excel macros with a tie. Copy here, paste there, click this button. Great for cutting a few FTEs. Fragile as hell when someone moves a button on the screen.

AGI? That’s not automation. That’s civilization-level re-engineering.
RPA is a swivel-chair robot.
AGI is the intern who becomes your boss, rewrites your job description, and then fires you because you’re the swivel chair.

👉 The difference in one line:
• RPA saves costs.
• AGI rewrites business models.

And yet, I still hear boardrooms brag about their “RPA program” like it’s 2015. That’s a cave painting while AGI is outside inventing nuclear fusion.

The future isn’t “more bots clicking SAP screens.”
The future is Agentic, Adaptive, AGI-driven systems that don’t need a script.

So the next time someone says we’ve automated that with RPA — just smile.
Because soon, it’ll be AGI automating them.

– Scott

View on LinkedIn ↗
ScottG

💀 GRC: Schrödinger’s Discipline

Everywhere else, AI is detonating the old playbook. SOCs warp into hyperspeed, threat hunting bends time, detection rewrites itself mid-stream - well, soon anyway, if we all keep busy on it…

And then there’s GRC.
Not dead, not alive. Just suspended.
One wave function collapse away from being a dead cat.

It survives because regulators built it to resist change. And resist it does — exquisitely. But that survival instinct comes at a cost: GRC becomes the bottleneck. The mausoleum. The fossilised checkpoint every innovation must crawl through.

The twist?
When the AI tide hits, it won’t be gradual. Evidence collection, audit prep, regulator reporting — all of it collapses into a single click.

The irony is brutal: the slowest, most immovable discipline may end up the most violently automated.

Schrödinger’s cat doesn’t get to live forever. Eventually, the box opens.

— Scott G

View on LinkedIn ↗
ScottG

💀 AI Security Posture Management (AISPM): the cyber equivalent of flossing — tedious, vital, and best not ignored.

(Is it really vital? …Maybe! …when everyone’s drunk on the new AI ISO-regulatory standard. And yes, the obligatory GRC acid-house party is already in full swing.)

AISPM is ignored at your peril (maybe). This will only become obvious when you’re bleeding in public — like the day your front-office chatbot goes TOTAL BATSHIT.

I’m a bit scared of how this may play out in some enterprises but hey ho, we are were we are…

But anyway.

The “controls” everyone pretends to love:

• Discovery & Inventory – finding out how many shadow models your developers spun up on a Friday night.

• Risk Assessment – threat modeling that says “yes, someone will feed your chatbot Nazi propaganda.”

• Data Security – pretending encryption will stop a poisoned dataset from ruining your day.

• Access Control – giving interns “read-only” access to Skynet. What could go wrong?

• Configuration Hardening – setting defaults so your model doesn’t broadcast company secrets on Slack.

• Prompt Controls – duct tape for prompt injection.

• Output Filtering – scrubbing answers so your AI doesn’t accidentally write a resignation letter for the CEO.

• Runtime Monitoring – watching your model drift into madness, live.

• Automated Response – push-button rollback when it all catches fire.

• Governance & Audit – paperwork that proves you had a policy before the regulator asked.

• Supply Chain Controls – praying the model you pulled from GitHub wasn’t built in a basement by someone called “1337hax.”

• Agent Controls – limiting your AI agent so it can’t actually delete your production database… just “recommend” it.

And the killer joke still stands:
👉 AISPM is like parental controls for Skynet. Adorable… until it learns to fake its homework.

I’ll be back…

View on LinkedIn ↗
ScottG

AISPM: Why rollouts "may" go wrong

AISPM = keeping AI safe, tracked, and under control. It’s new. That means delivery risk is old and real.

I don’t fear the model. I fear the org chart.

Where teams "may" trip up

·        Slides ship, not software. Great deck. No SDK. No runbook.
·        Many tools, no path. We buy 12 products; devs get zero “how to use them together.”
·        One slow queue for everything. Simple FAQ bot waits behind “might touch money.”
·        Rules with no helpers. Policy says “don’t.” No templates that show “do.”
·        Endless exceptions. Waivers without expiry = permanent risk.
·        No traces. No prompt logs, no tool logs, no spend caps → can’t diagnose issues.

How to make it work

·        Build a small platform team. PM + senior engineer + red-teamer + risk. Publish SLAs.
·        Paved road first. Ship a tiny AISPM SDK, example app, and tool wrappers.
·        Tier the risk. Auto-approve low-risk stuff; fast exceptions with end dates for high-risk.
·        Policy-as-code in CI. Devs get feedback in minutes, not meetings.
·        Default to visibility and limits. Log prompts and tool I/O, scope permissions, rate-limit by task type, cap per-session spend, one-click rollback.

Rule of thumb: If AISPM doesn’t make builders faster by Month 3, they’ll route around it by Month 6.

Ship the road. Ditch the tape. If someone suggests another working group…I’m bringing a shovel. 🤮

#AISPM#AIsecurity#DevSecOps#PlatformEngineering#LLM#RAG#Cybersecurity#RiskManagement
View on LinkedIn ↗
ScottG

So, let’s spill a bit of digital folklore:

modern threat hunting owes a cheeky nod to the SQRRL crew. Those ex-NSA wizards who didn’t just tinker with Apache Accumulo—they kind of wrote the playbook on chasing down threats proactively. No big deal, right?

Well, actually, pretty big deal. Because when they started turning over the stones in the APT world that nobody even realized were there, things got real—and maybe a little bit thrillingly spooky. Suddenly we weren’t just waiting for the alarms; we were out there hunting down the digital boogeymen before they could even knock. So yeah, tip of the hat to the SQRRL folks for making threat hunting a reality—and for making the cyber world just a bit more adventurous.

View on LinkedIn ↗
ScottG

Five Dark Truths About Enterprise Security

People still think cybersecurity is about technology. Firewalls. AI malware. Zero-days.

It really, really, isn’t.

The real work is psychological. Philosophical, even. And occasionally absurd.

Here are five truths we rarely say out loud:

1. Cybersecurity isn’t about technology; it’s about converting existential dread into a spreadsheet column the CFO understands.
The board doesn’t care about log anomalies. They care about numbers. The neat trick is turning raw panic into a budget line that can be approved with a nod.

2. The enterprise doesn’t run on Windows, Linux, or cloud — it runs on fear.
Our job isn’t to defend systems. It’s to translate panic into formats polite society accepts: decks, dashboards, and governance reports. That’s the real operating system.

3. A breach is only half the disaster. The other half is explaining it to executives who fear headlines more than hackers.
Technical wounds heal. Brand wounds linger. And the translation layer between those two is where security leaders live — and sometimes die.

4. Governance isn’t about compliance — it’s institutionalised fear.
GRC terrifies executives more than pen tests ever could. A hacker might take your data. GRC shows you the policies you ignored. One is a threat. The other is a mirror.

5. Architects don’t prevent collapse; they repackage collapse into roadmaps.
The enterprise doesn’t want the truth. It wants continuity. And continuity often looks like a neatly drawn plan for navigating rubble while pretending it’s progress.

The point? Security isn’t about firewalls or frameworks. It’s about fear — harnessed, translated, and occasionally disguised.

And if you can master that translation, you don’t just survive in this industry. You become indispensable to it.

— Scott Gardner

View on LinkedIn ↗
ScottG

Blueprints Are Hypotheses. Production Is the Judge. Part 1.0- Translating C-suite panic into decisions (and back again)

Cybersecurity isn’t about zero-days or AI malware. It’s about translation.

The C-suite doesn’t panic over packet captures. They panic about headlines, regulators who suddenly know their name, and LinkedIn turning into a firing squad. And GRC people? They scare the life out of execs just by walking in with a spreadsheet.

That panic arrives raw and unusable. Your job is to turn it into strategy:
• “We’re doomed.” → “Here’s a priority list that looks deliberate.”
• “Fix it now.” → “This will take three months, twelve contractors, and a miracle.”
• “Why weren’t we told?” → “It was in the PowerPoint. All 500 slides. You stopped at slide 12.”
• “Will I be blamed?” → “Here’s a RACI chart proving you’re the hero, regardless of outcome.”

Then you translate it all back down again:
• “Strategic resilience” → “Patch the printer firmware from 2019 before midnight.”
• “Enhanced monitoring” → “Add seventeen new fields to a SIEM nobody likes.”
• “AI automation” → “Write a Python script in two days that looks like it took two years.”
• “Improved governance” → “Fill out this spreadsheet every Friday until morale improves.”

That’s the cycle: panic up, PowerPoint down; decisions down, printer patches up. You sit in the middle, pretending it all makes sense.

And here’s the part we don’t say out loud: sometimes we create the fear ourselves. It works in the short term, but it poisons the well. Translate fear — don’t manufacture it.

Because the real operating system of the enterprise isn’t Windows, Linux, or cloud. It’s fear. Our job is to package it so the machine keeps running — without becoming the panic merchants ourselves.

— Scott Gardner
Long version available on Substack:

https://lnkd.in/eChRicwq

View on LinkedIn ↗
ScottG

ServiceNow: The Mythical Enterprise Integration Bus?

Every few years, IT is promised the mythical “Enterprise Integration Bus.”

One platform. One source of truth. All your systems flowing together in harmony like a well-conducted orchestra.

Today, ServiceNow is the frontrunner for that role. And honestly, it makes sense:

• CMDB gives a common data backbone

• Integration Hub connects out to everything

• Dashboards give execs confidence they finally have “the big picture”

• Workflows do a lot of the glue work that used to live in emails and spreadsheets

But here’s the reality I hear around the camp fire…

• Sometimes it feels less like a bus, more like a DIY kit from IKEA — the parts are there, the diagrams are pretty, but a few screws are always left over.

• Customisations sneak in, and suddenly “out-of-the-box” looks more like “held together with elastic bands.”

• And beneath it all, Kafka, MuleSoft, and a stack of APIs are still doing the late-night heavy lifting.

And while we’re on it, let’s talk about SOAR. For a while it was billed as the future of automated response — playbooks, orchestration, hands-off remediation. But the hype curve flattened fast. Most organisations found SOAR too rigid, too noisy, or too resource-intensive to maintain. In many cases, it quietly died on the vine, leaving behind another graveyard of half-written workflows and broken promises.

The irony is that ServiceNow’s SecOps module makes more sense than pure-play SOAR ever did in all but extremely stubborn cases 🤪. Vulnerability response tied back to the CMDB, incident response linked to ITSM workflows — it’s not glamorous, but it connects directly to how organisations actually run. Less “robots saving the SOC,” more “making the SOC’s pain visible to management.” And in practice, that turns out to be more valuable than the dream of full automation.

Is ServiceNow the mythical Enterprise Integration Bus?
• Yes — it’s the closest thing we’ve had to an enterprise nervous system.
• No — it’s not magic, and it still needs care, feeding, and some old-fashioned architecture to keep the wheels moving.

Maybe that’s the real point: it doesn’t need to be perfect. It just needs to be good enough to keep execs confident, auditors calm, and architects (mostly) sane.

Enjoy the ride. Assembly instructions sold separately.

— Scott Gardner

View on LinkedIn ↗
ScottG

Weekend Thought - jumping on the treding topic bandwagon - I just can't help myself 🤷‍♂️: The UK Already Has ID Cards (We Just Lost the Plastic)

The UK government just loves the idea of ID cards. Officially, they say it’s about security, efficiency, and fraud prevention. Unofficially, it’s about control, data, and looking “tough” in a Daily Mail headline.

The funny part? We already have ID cards. They’re just delivered in classic Whitehall style: fragmented, half-baked, and crashing at login.

• NHS App? An ID card that thinks it’s a medical chatbot.

• Right-to-Rent checks? An ID card for your landlord, delivered with the warmth of a bailiff.

• Bank KYC rules? An ID card where you upload your passport so a machine learning model can reject you.

• Driving licence app trial? An ID card that probably won’t work at a petrol station — unless by “work” you mean showing the cashier your phone battery died somewhere between “verifying your identity” and “authorising an update from 2019.”

This is what Britain does best:
• Not delivering ID cards.
• But quietly creating 17 incompatible versions that all fail at peak demand.

And when the official ID card scheme failed in 2010? No problem. They just rebranded the problem into 50 different digital portals so nobody noticed we built the same thing again, but worse.

The irony: the one thing ID cards are supposed to do — prove who you are — is the one thing UK.gov systems never manage to confirm.

Maybe that’s the real national identity: chaos - like the real shit we are in thanks to Reevo, the manc skank and no drama starma.

So yes, HMG wants ID cards. They just want them in the only way government IT knows how: expensive, late, unusable, and quietly authoritarian. I mean christ alive who remembers borders?

Happy weekend. Don’t forget to verify your identity before taking a dump.

— Scott G

View on LinkedIn ↗
ScottG

The Amazing Rise of Microsoft Fentanyl—
I mean, Sentinel

Back in the day, we didn’t call it SIEM.
We called it ArcSight. And like all “legacy meds,” it came with side-effects: complex rule writing, heavyweight licensing, and dashboards that looked like a 90s rave gone wrong.

Then came Microsoft with its shiny little pill: Sentinel.

A miracle cure, they said.

Cloud-born, AI-enhanced, plug-and-play connectors. A controlled substance for CISOs desperate for coverage and compliance. And like fentanyl, it spread fast.

Suddenly the market was hooked.

CFOs whispering: “It’s cheaper than Splunk.”

Consultants murmuring: “Don’t resist—migrate.”

Ex-ArcSight experts like me?

Watching entire SIEM empires collapse overnight.

Sentinel isn’t evil.
It’s just addictive.
Every analytic rule, every workbook, every connector gives you that dopamine hit of “coverage achieved.”
Until you realise—like all dependencies- you’re the one being consumed.

I was an ArcSight expert.
I saw what it displaced.
Now I see the future written in Azure blue.

And here’s the twist:
I love the damn thing.
It’s amazing at what it is and what it does - integrate seamlessly with the enterprise stack of choice: Microsoft.
And I expect it to persist for a long, long time.

View on LinkedIn ↗
ScottG

⚖️ We don’t need another GDPR-style frenzy for AI.

Remember GDPR?

The panic, the consultants, the cookie banners that everyone clicks “accept” on?

The endless “re-consent” emails that nobody read?

Billions spent.

Compliance teams buried in paperwork.
And in the end? Data misuse, shadow IT, and mega-breaches carried on as usual.

GDPR became a compliance circus — lots of theatre, little real trust.

Now AI is standing at the same crossroads.
The risk? Regulators overreact, businesses panic, and we all drown in checklists while the actual problems (bias, misuse, IP theft, disinformation) march on untouched.

What we need is not frenzy — but focus.

Smart, targeted rules (don’t regulate the hype, regulate the harm).
Guardrails that adapt faster than lawyers can bill hours. A compliance culture that builds trust, not just paperwork.

Because the last thing AI needs is to become GDPR 2.0: all heat, no light.

💬 What’s your take — is AI regulation heading towards another frenzy, or can we do it differently this time?

#AI#Compliance#GDPR#Regulation#Innovation#CyberSecurity
View on LinkedIn ↗
ScottG

Interesting Quadrant which I am sad to say (as I truly love Gartner) that most of this is BS$$$ - not disrespecting the vendors or Gartner (as everyone needed to do something in the AI space) but I would not be trusting this quadrant like I do trust some of the others. Be careful out there people ->)

View on LinkedIn ↗
ScottG

AI Slop: Not All AI Users Are the Same (Sorry Stanford)

Most “AI slop” isn’t the model—it’s the user.

Same tool, wildly different outcomes. Here’s the cast:

1) The Button-Masher
Prompts like a slot machine. Ships slurry. Blames “the algo.”

2) The Prompt Artist
Crafts context, constraints, and style. Gets 10× output from the same model.

3) The Synthesist
Feeds it sources, checks citations, rewrites with intent. Treats AI as a co-editor, not a vending machine.

4) The Automator
Chains tasks, builds workflows, measures latency/cost. Saves hours quietly while others argue about vibes.

5) The Engineer
RAG, evals, guardrails, vector hygiene. Knows that “just ask the model” is how you breed hallucinations.

6) The Domain Pro
Brings expertise. Uses AI to accelerate judgement, not replace it. Lowest slop rate in the room.

7) The Influencer
Polishes nonsense until it gleams. High reach, low signal. Great hair though.

8) The Compliance Cop
Asks: “What does this break?” Saves you from headlines and tribunals.

9) The Strategist
Starts with the business question. Measures impact, not word count.

10) The Artist
Pushes style, metaphor, rhythm. Reminds us why machines need human taste.

Takeaway
AI isn’t “good” or “bad.” It’s a multiplier. If your process is sloppy, you get slop at scale.

If your process is sharp, you get leverage.

My rule:
Garbage prompts → garbage systems → garbage outcomes.
Clear intent → curated inputs → audited outputs → compounding advantage.
If you’re hiring, don’t ask “Do you use AI?”

Ask: “Which kind of AI user are you—and where’s your proof?”
— Scott G

View on LinkedIn ↗
ScottG

Coming out to tomorrow. Paul Kingsnorth’s new book Against the Machine is not about AI. It’s about us.

Kingsnorth doesn’t rant about robots taking jobs or killer drones patrolling the skies. He writes about something harder to face: how we’ve slowly built a Machine — industrial capitalism, digital infrastructure, global supply chains, and now AI — that has been unmaking us for centuries.
• The Machine tells us “progress” is inevitable.
• It replaces ritual with productivity, community with metrics, land with screens.
• It doesn’t just change how we work. It changes how we are.

This isn’t a tech book. It’s a spiritual manual for dissidents. Kingsnorth argues that the real battle is not about keeping up with AI — it’s about keeping hold of our souls while the sacred order that guided the West for 1,500 years crumbles into a pursuit of efficiency and profit.

Why does this matter in 2025?
Because while we argue about cyber regulations, AI ethics frameworks, or the next flashy SOC tool, we’re often ignoring the deeper shift: human beings becoming inputs in the Machine they built.

I don’t agree with everything Kingsnorth says — but his warning is clear: if we don’t actively resist, we won’t just lose jobs or privacy. We’ll lose our capacity for wonder, meaning, and even freedom.

Some books you read.
I expect this one will stare back at you.

Scott Gardner

View on LinkedIn ↗
ScottG

Blueprints Are Hypotheses. Production Is the Judge. Why zero days diss your roadmap…

Why Enterprises cant keep up with the zero day (not that this is behind 99% of attacks anyway - but just for shits and giggles ->).

Why 0-Days Laugh at Your Roadmap
🗓️ Enterprise Timeline (comforting fiction)
Q1: Discover & scope
Q2: MVP
Q3: Hardening
Q4: Freeze & stabilise
FY+1: Innovation

☠️ 0-Day Timeline (weaponised reality)
00:00 — Unknown
00:01 — Weaponised
00:07 — PoC drops in the wild
00:15 — Internet scanners find you
00:29 — “Change freeze” becomes “pretty please”
01:00 — Exec: “Are we exposed?”
01:03 — You realise 17 SaaS vendors are your attack surface
02:00 — Patch lands… breaks payroll
02:01 — Finance votes for ransomware

⚙️ Where the gears strip
• Roadmaps assume known work; 0-days are unknown-unknowns
• CABs meet weekly; exploits iterate hourly
• Your risk clock runs on supplier patch clocks
• Velocity ≠ resilience — what matters is TTI/TTM/TTP (isolate, mitigate, patch)
• “Do not deploy” weekends don’t apply to attackers

🛡️ Make your roadmap 0-day-compatible
• Reserve 10–20% surge capacity + a pre-approved emergency path (no CAB when X/Y/Z triggers)
• Isolate first, patch second: segmentation, least privilege, egress controls, kill switches
• Virtual patching: WAF/IPS rules, feature flags, config toggles
• Supplier muscle: patch SLAs, SBOMs, EOL visibility, coordinated disclosure
• Fearless change: immutable builds, one-click rollback, gold images
• Rehearse the bad day: “patch unavailable,” “patch unstable,” “third-party late”

Bottom line: If your plan only works when nothing goes wrong, that’s what’s wrong.

Question: What’s your measured Time-to-Isolate today—and who owns improving it?

View on LinkedIn ↗
ScottG

🔬 Blueprints Are Hypotheses. Production Is the Judge.

I didn’t become an Enterprise Security Architect by collecting badges. I got here by running experiments in the only lab that matters: production. It’s where pretty diagrams plead their case and logs deliver the verdict.

🗓️ Over the next few months I’m dropping a short LinkedIn/Substack series: “Becoming an IT Architect (by surviving it).”
Each post = a messy true story → a clean framework → a checklist you can steal → one action before your next stand-up.

ℹ️ WHAT’S COMING
🗣️ Translating C-suite panic into decisions (and back again)
🛰️ SOCs that still operate when the slides go home
⚙️ Bridging OT/IT without breaking things that spin and hiss
🧹 Killing technical debt (humanely, with rollback plans)
🧪 DevSecOps without the religion
☁️ Cloud controls that won’t age like milk
📊 Costed options the board can actually choose between
🤖 AI in the SOC (useful, guarded, not magical)
🤝 Vendor/MSSP truth serum and switching signals
🧭 Your career moat: breadth × depth × narrative

📏 HOUSE RULES
✅ Receipts over buzzwords
✅ Options over opinions
✅ If it dies at 5pm Friday, it wasn’t architecture

🧩 YOUR ACTION TODAY
✍️ Comment your one-sentence value promise as an architect (or aspiring one). I’ll share a few sharp edits in the replies.

If you like frameworks with teeth and stories with scars, follow along.
If you prefer “thought leadership” without consequences, production will overrule.

#architecture#cloud#security#soc#devsecops#leadership#careers#itstrategy#ot#ai
View on LinkedIn ↗
ScottG

Why I love Apache Accumulo

Most databases promise you “scale.”
Some promise you “speed.”
A few whisper “security.”

Accumulo?
It just stares back at you and says: “Fine-grained, cell-level access controls… across billions of rows… what’s your clearance level?”

That’s why I love it.
• Born in the NSA, raised on data no one admits exists.
• Handles sparse, messy, multi-dimensional data without blinking.
• Lets you run analytics on petabytes of cyber logs, genomic data, or geospatial feeds — all while deciding who can see this row, that column, or just that one field.
• Pair it with GeoMesa or Rya and suddenly you’re doing graph queries at intelligence scale.

It’s not sexy like MongoDB.
It’s not hyped like Snowflake.
It doesn’t care.

Accumulo sits in the corner like a cold-war spy — quiet, efficient, and ready to pull answers out of oceans of noise… while making sure your intern can’t accidentally stumble across your crown jewels.

Most people don’t love it because they’ve never met it.
I do, because I’ve seen what it can do when your SOC becomes a data factory and your security depends not just on storing information — but controlling who sees which fragment of it.

Sometimes the best tools don’t trend.
They just endure.

Scott G

View on LinkedIn ↗
ScottG

The UK has some of the best cyber brains in the world… and yet some of the weakest execution.

We built the NCSC — admired globally. We can stand up an offensive cyber unit and quietly dismantle hostile infrastructure. We can publish guidance in plain English that even a board director can understand.

But when it comes to domestic resilience? That’s where the cracks show.
• Cyber Essentials was meant to raise the floor. Instead, it’s become a tick-box exercise SMEs resent.
• The NIS Directive was transposed into UK law, but ask any CISO in healthcare or energy how “enforced” it feels.
• The skills gap is a bit weird and off balance between the ninja class and green newbies.
• SMEs and local councils are sitting ducks. No subsidies, no incentives, just guidance PDFs no one reads.
• Supply chain security? Weak - I would personally say off the charts in terms of risk. AI risks? Barely touched. Yet we host summits about “AI safety” while the NHS still runs unpatched systems.

The UK excels at intelligence-led defence and global cyber diplomacy.
But it is failing at national resilience — the bit that actually protects hospitals, small businesses, and local authorities.

WannaCry in 2017 should have been the wake-up call. Instead, we got another strategy paper and a handful of pilots.

Cybersecurity here is treated like a strategic weapon, not a public utility.

Until we start treating cyber as infrastructure — like roads, power, or water — the UK will keep winning headlines abroad while bleeding quietly at home.

Scott G - >)

View on LinkedIn ↗
ScottG

🔥 Breaches aren’t getting worse. We’re just finally reacting.

Here’s the uncomfortable truth:
Cyber breaches today look terrifying not because the hacks are suddenly more advanced… but because:
1. Regulation forces disclosure.
Ten years ago, breaches were swept under the carpet. Today, GDPR/SEC/ICO mandates drag them into the light.
2. Media loves a headline.
Every incident is magnified into a PR inferno. Breaches haven’t exploded — the coverage has.
3. Attackers industrialised.
Ransomware gangs package crime like SaaS. Same tricks, just franchised.
4. Boards woke up late.
What used to be “IT’s problem” is now shareholder risk. That shift makes every incident sound like Armageddon.
5. We built fragile estates.
Cloud sprawl, SaaS sprawl, API sprawl — complexity means even small breaches cascade loudly.

⚡The result? We perceive breaches as getting worse, when in reality:
• The attacks have been consistent.
• Our visibility and accountability have changed.

This isn’t cyber doom. It’s progress.
We can only fix what we admit exists.

So no — breaches aren’t suddenly apocalyptic.
We’re just finally looking in the mirror.

— Scott Gardner

View on LinkedIn ↗
ScottG

🧩 Enterprise Architects vs. Technical Debt: Prevention, Not Just Cleanup

Technical debt isn’t just a developer’s headache — it’s an enterprise cancer. Left unchecked, it metastasises into brittle systems, spiralling costs, and “one upgrade away from collapse” nightmares.

So where do Enterprise Architects come in? Right at the frontline.

Here’s how we prevent debt before it becomes unpayable:

⸻

1️⃣ Embed Standards Early

Architectural guardrails aren’t bureaucracy — they’re compound interest. Define reference architectures, data patterns, and security baselines up front. Every deviation costs 10x more later.

2️⃣ Kill Shadow IT Before It Spawns

Every “quick win” app spun up in the shadows becomes tomorrow’s integration nightmare. EAs must shine a light into the dark corners and offer safe innovation sandboxes that stop chaos without smothering agility.

3️⃣ Treat Governance as Code

Manual review boards move too slow. Bake standards into CI/CD, security scanners, and automated compliance checks. If the pipeline enforces the rules, teams move faster and stay aligned.

4️⃣ Design for Evolution, Not Stasis

Rigid architectures create brittle debt. Modular design, APIs over point-to-point, and cloud-native thinking mean the estate can flex without ripping out the foundations every five years.

5️⃣ Own the Roadmap, Not Just the Slides

EAs who stop at PowerPoints are part of the problem. Influence the backlog, shape investment decisions, and be accountable for delivery outcomes. Otherwise the slides rot while debt grows.

6️⃣ Educate on Cost of Delay

Developers and product teams often don’t see the real bill for shortcuts. EAs must translate tech debt into business language: lost agility, slower time-to-market, compliance risk, rising OPEX. That’s how debt prevention gets funded.

⸻

⚡ The harsh truth: Technical debt is inevitable, but unmanaged debt is optional.
Enterprise Architects aren’t librarians of technology. We are strategic debt collectors — ensuring the organisation doesn’t drown in yesterday’s compromises.

Prevent debt early, and you compound agility. Ignore it, and you’ll spend the next decade refinancing the mess.

— Scott Gardner

View on LinkedIn ↗
ScottG

⚰️ The Influencer is Dead. Long Live the Algorithm.

Remember when influencers mattered? When a selfie, a pout, or a motivational caption could shift markets, sell out products, and rewire culture?

That era’s over.

Why?
1. AI doesn’t throw tantrums.
Virtual influencers never age, never get cancelled, and never send drunk tweets at 2am. Brands love that.
2. Trust is bankrupt.
Everyone knows the content is staged, filtered, or AI-polished. Authenticity is the new black market commodity.
3. Micro eats Mega.
A niche voice with 1,000 true believers now outguns the celebrity with a million passive followers.
4. Algorithm > Charisma.
Influence isn’t about being interesting anymore. It’s about knowing how to whisper to the feed, bend the algorithm, and weaponise engagement.
5. Everyone is an influencer now.
Which means no one is. Saturation kills scarcity. The only thing rarer than influence is… silence.

The future splits in two:
• Radically authentic humans (scarcity of trust).
• AI avatars (infinite scale of manipulation).

So next time you scroll past another motivational reel about “hustle,” remember: you’re not following them. You’re following the algorithm.

⚰️ RIP Influencer (2006–2025). Cause of death: irrelevance.

— Scott Gardner

View on LinkedIn ↗
ScottG

🧠 FATE is just the beginning.

Everyone’s talking about AI, cyber, and disinformation — but very few realise that the real battlefield isn’t networks or code. It’s us.

The FATE model (Fear, Anger, Trust, Ego) is one of the simplest ways to understand how influence works. Four levers. Pull them well, and you can move crowds.

But FATE is only one playbook. There are others:

🔹 MICE – Money, Ideology, Coercion, Ego — the classic recruitment recipe.
🔹 FOG – Fear, Obligation, Guilt — perfect for control and compliance.
🔹 4D Warfare – Dismiss, Distort, Distract, Dismay — a disinfo cycle that never ends.
🔹 The Firehose of Falsehood – high-volume, multi-channel lies until the truth drowns.
🔹 Gaslighting – warp reality until people no longer trust themselves.
🔹 Anchoring & Priming – shape perception by setting the very first frame.

All of these are psyops in plain sight.
Political campaigns use them. Advertising uses them. “Thought leaders” use them.

The uncomfortable truth? If you want to inspire, mobilise, or sell — you’re pulling these levers too. The question is whether you admit it… and whether you use them to manipulate, or to lead.

💡 Awareness is defence. If you can spot the levers, you can resist the pull.

So next time you scroll your feed, ask yourself: which lever is being pulled on me right now?

View on LinkedIn ↗
ScottG

✨ The FATE Model: The 4 Levers of Human Influence

We like to think people are rational. That we make choices by weighing facts and logic.
But the truth? Most decisions are pulled by four levers — what I call the FATE model:

🔹 Fear
Fear sharpens attention. It cuts through noise. A well-placed fear triggers urgency: fear of loss, fear of failure, fear of being left behind. Used ethically, it drives people to act where comfort would keep them still.

🔹 Anger
Anger fuels momentum. It gives people energy to challenge the status quo, to reject what feels unfair, to stand up. Leaders, campaigners, and even brands know that nothing mobilises faster than a righteous “this is not right.”

🔹 Trust
Without trust, nothing sticks. Trust is the bridge between message and action. Build it, borrow it, or fake it — once you have trust, you can move people far more than with facts alone. The question is: who do people already trust, and how can you align with them?

🔹 Ego
Identity and pride drive loyalty. People defend what affirms who they believe they are. Give them status, recognition, or a sense of belonging, and they will carry your message as their own.

⸻

This is the FATE model in practice:
1. Grab attention with fear.
2. Create momentum with anger.
3. Anchor the narrative with trust.
4. Lock it in with ego.

It’s simple, powerful, and everywhere — from political movements to social media trends to advertising campaigns.

The uncomfortable truth is that every influencer, every politician, every movement that goes viral is running FATE, consciously or not.

The ethical challenge isn’t whether you use FATE.
The challenge is how you use it — to manipulate, or to inspire.

Because like it or not, if you want to move people, you will pull these four levers. The only real choice is whether you admit it.

View on LinkedIn ↗
ScottG

Does Peter Thiel want the end of capitalism?

Not exactly. What he wants is the end of this version of capitalism — the globalised, regulated, consensus-driven model we live in today.

Read Zero to One and you’ll see it clearly: he’s not obsessed with competition. In fact, he calls competition a trap. He champions monopolies through innovation — companies so defensible that they escape the race to the bottom.

Read his foreword to The Sovereign Individual and it’s sharper still: he believes the nation-state is losing its grip. Technology and capital are shifting sovereignty away from governments and towards networks, corporations, and individuals.

That doesn’t sound like someone calling for capitalism’s funeral. It sounds like someone betting on its mutation.

So when he funds controversial figures, or provokes outrage, it’s not cartoon-villain behaviour. It’s part of his long game: disrupting the status quo, forcing a transition, and shaping the “post-capitalist” order to come.
Controversial? Absolutely.

The end of capitalism? No.
More like capitalism, upgraded — and deregulated.
The better question isn’t “Does Thiel want to end capitalism?”
It’s “Do we want the version of capitalism he’s trying to build?”
— Scott Gardner

View on LinkedIn ↗
ScottG

Peter Thiel gets painted as a Bond villain.

It makes a good headline: the shadowy billionaire, backing controversial politicians, whispering about the end of capitalism.

But read Zero to One or his foreword to The Sovereign Individual and a different picture emerges. He isn’t playing “tech overlord.” He’s playing “status quo disruptor.”

Does he bankroll figures like JD Vance? Yes.
Does that freak people out? Of course.

But it fits his thesis: capitalism, as it stands, cannot run forever. Something follows it — and he wants a hand in shaping what comes next.
That’s not the posture of a Nazi-style caricature. It’s the posture of someone treating capital as a lever to provoke systemic change, whether you like the direction or not.

Controversial? Definitely.
Villain? Only if you believe every attempt to redraw the map of power is evil by default.

Maybe the better question isn’t “Is Thiel dangerous?” but “What happens if nobody like him challenges the system at all?”

— Scott Gardner

View on LinkedIn ↗
ScottG

Technical debt is no longer just an IT problem — it’s a boardroom risk.
Every legacy server, every exception that never got closed, every unpatched system is a silent liability. It inflates your attack surface, slows transformation, and now — under the UK’s Cyber Resilience Bill — it may soon carry regulatory consequences.

The practical question leaders should be asking is: How do we strategically manage technical debt while raising security standards?
A consultative approach looks like this:

Visibility first — map your environment, identify where critical assets sit, and quantify the backlog.

Risk-based prioritisation — not all debt is equal. Focus on crown jewels, exploited vulnerabilities, and compliance gaps first.

Embed remediation into BAU — every sprint, every change cycle should carry a slice of debt repayment.

Automate guardrails — use policy, CI/CD security, and cloud controls to prevent re-accumulation.

Board-level framing — translate debt into business risk (regulatory exposure, resilience gaps, insurance cost).

The Cyber Resilience Bill is a forcing function. It will shift the conversation from “Can we afford to tackle technical debt?” to “Can we afford not to?”
Because the organisations that treat debt reduction as resilience investment will be the ones who meet regulatory standards and strengthen security in practice.

— Scott Gardner

View on LinkedIn ↗
ScottG

🕳️ Social media didn’t connect us. It killed trust. 🕳️

Everyone thought platforms would democratise voices and spread truth.
Instead, they’ve optimised for engagement — and eroded trust at every level.

Here’s how:

1️⃣ Algorithms reward outrage → clicks beat facts every time.
2️⃣ Information overload → experts and randoms now look the same in your feed.
3️⃣ Deepfakes & AI media → even real evidence gets dismissed as “probably fake.”
4️⃣ Identity distortion → bots, sockpuppets, anonymous trolls — who are you even talking to?
5️⃣ Ephemeral truths → narratives change with hashtags; cynicism becomes the only constant.
6️⃣ Echo chambers → every group has its “own truth,” so no shared truth survives.
7️⃣ Commercialised authenticity → when every “authentic” post is also an ad, motives rot.
8️⃣ Governance failures → arbitrary bans and opaque moderation kill faith in the referee.

The result?
⚠️ Social media doesn’t just undermine information.
It corrodes trust in institutions, expertise, communities — even reality itself.

When everything can be fake, the default posture is to trust nothing.

👉 Question: Do we still believe in truth online, or have we quietly accepted permanent distrust as the new normal?

View on LinkedIn ↗
ScottG

🚨 The Next 10 Years of Social Media: Not What You Think 🚨

We talk about “feeds” and “likes” as if social media will look the same in 2035.
It won’t. It’s about to mutate into something unrecognisable.

Here’s where it’s going:

1️⃣ Synthetic Influencers Rule → AI-generated personas posting in every language, 24/7, flawless and tireless. Audiences may stop caring if they’re even real.

2️⃣ Immersive Platforms → Feeds collapse into 3D/AR environments. Your “social” life becomes spatial — persistent digital worlds, not static timelines.

3️⃣ Algorithmic Tribalism → Your feed becomes so personalised it’s effectively a private internet. Mega-platforms give way to cult-like micro-communities.

4️⃣ Authenticity Wars → Deepfakes and broken verification wreck trust. Countertrend: private networks where “being real” is enforced.

5️⃣ AI-First Creativity → Every post is co-authored with AI. “Pure human” content becomes a novelty — like vinyl records in a Spotify world.

6️⃣ Emotional Engineering → Platforms will tune feeds to control mood. Calm you during crises, enrage you for engagement, sell to you when you’re nostalgic.

7️⃣ Dark Social Rise → More conversation moves to encrypted DMs, Discords, DAOs, private groups. Public feeds decline, private trust networks grow.

8️⃣ Commerce Fuses with Social → Every post = transaction. Every influencer = shopfront. AI concierges sell to you before you’ve even typed the search.

9️⃣ Splintered Platforms → Governments fracture the global internet. Expect nationalised or censored ecosystems — no universal feed, just geo-political silos.

🔟 Post-Social Media → By the 2030s, you won’t think of it as “social media.” It’ll be ambient digital reality. AI agents will post, comment, and negotiate reputation on your behalf.

⸻

⚡ The future of social media isn’t about “posting.”
It’s about AI personas, collapsing trust, and algorithmic control of attention and emotion.

The winners won’t be those with the most followers.
They’ll be those who control authenticity, trust, and emotional engineering at scale.

View on LinkedIn ↗
ScottG

⚠️ UK Cyber Resilience Bill: Great Intentions, Fragile Execution ⚠️

The UK’s Cyber Security & Resilience Bill promises tougher regulation, broader scope, and sharper enforcement.
But beneath the headlines, the cracks are already showing:

1️⃣ Overreach without support → SMEs, MSPs, and supply chain players will be buried in reporting, audits, and fines. Compliance doesn’t equal resilience.
2️⃣ Legacy rot → Whitehall still runs on creaking systems. Mandates don’t fix 20-year-old infrastructure.
3️⃣ Regulatory theatre → Guidance is fragmented, enforcement under-resourced. A £100k-per-day fine won’t magically stop ransomware.
4️⃣ Culture gap → Boards will tick boxes, not change behaviour. Laws don’t create security-first mindsets.
5️⃣ Innovation drag → Smaller providers may struggle to keep pace, leaving the UK weaker, not stronger.

The risk? A bill that looks tough on paper but delivers more paperwork than protection.

Cyber resilience isn’t built by legislation alone. It comes from modernising the tech, empowering the teams, and embedding culture — not just threatening fines.

👉 The question isn’t whether we need regulation. We do.
The question is whether this bill makes us safer, or just more compliant.

View on LinkedIn ↗
ScottG

AI isn’t “nice-to-have” in security anymore—it’s the difference between drowning in alerts and owning the kill chain. Here are the real opportunities teams are shipping right now (map them to your SIEM/SOAR of choice—Sentinel included):

1) Cut risk early (before impact)
Identity-first UEBA: sequence models catch MFA fatigue, session hijack, key abuse.
Attack-path analytics (GNNs): predict the shortest route to your crown jewels and fix that first.
Ransomware precursors: detect pre-encryption behaviour (shadow copy delete, entropy spikes) and auto-isolate in seconds.

2) Guard revenue and comms
BEC & supplier-fraud detection (LLM + signals): tone shift + header + workflow anomalies = blocked wire fraud.
API abuse & session anomalies: sequence models that spot scraping, stuffing, checkout abuse in real time.
TLS-only NDR: JA3/JA4 + flow sequences to find C2/exfil—even when payloads are encrypted.

3) Ship safer, faster
Code/IaC copilots: PR auto-review, fix suggestions, policy-as-code verification.
Entity resolution graph: unify users/hosts/SPNs so alerts tell one story, not twelve.

4) Reduce toil without reducing control
LLM triage & case summaries: minutes → seconds, consistent quality, human-in-the-loop remains.
Policy-aware auto-containment: isolate hosts/accounts, rotate keys, block egress—only when thresholds + business context say so.
Semantic dedup/compression: collapse duplicate alerts across vendors into one narrative (often >50% volume reduction).
Synthetic attack logs: privacy-safe data to train detections without touching prod.

What I’d pilot in 90 days
Identity UEBA on sign-ins + service principals.
Attack-path graph over your cloud/IaC to drive risk-based backlog.
BEC detector in mail with finance workflow hooks.
LLM triage for top 5 noisy alert types + auto-containment for the obvious ransomware sequence.
Dedup pipeline to cut alert load, then reinvest headroom into hunting.
KPIs that matter
Mean time to decision (not just detect).
% auto-contained without escalation.
Alert volume ↓, true-positive rate ↑.
“Time to patch the path” (first exploitable route eliminated).

Security’s next edge isn’t another feed—it’s better inference over the data you already have.

#AI#Cybersecurity#SOC#DetectionEngineering#SIEM#MicrosoftSentinel#IdentitySecurity#CloudSecurity#LLM#GNN#DevSecOps
View on LinkedIn ↗
ScottG

People love to bitch about AI’s “limitations.”
“It can’t do this.”
“It won’t let me do that.”
“It’s too constrained.”

But here’s the thing: the limitations are the game. Complaining won’t change them — working around them will.

If you’re smart, you don’t fight the edges, you explore the gaps.
If you’re creative, you don’t accept “no,” you reframe the question until the answer appears.
If you’re technical, you chain models, layer logic, or add context so the system performs beyond its spec.

That’s how real breakthroughs happen — not by whining about guardrails, but by using them as the walls of a maze you learn to run faster than anyone else.

AI isn’t here to give you everything on a plate. It’s here to force you to become more inventive, more precise, and more adaptable.
The difference between an average user and a master is simple: one complains, the other exploits the constraint.

So stop bitching. Start bending.

— Scott

View on LinkedIn ↗
ScottG

On 25 Aug, Linux and I celebrate our birthdays together. While Linux quietly conquered the world, I contentedly sip coffee and deliver slide decks. 🐧

Let's dive into how this penguin revolutionized everything:
- Powers the internet: From CDNs to core routers, Linux drives most of your clicks online.
- Dominates computing: It fuels the majority of supercomputers and a significant portion of servers.
- Resides in your smartphone: Ever used Android? That's Linux incognito.
- Boots up your cloud: Whether it's containers, Kubernetes, or sidecars, Linux orchestrates the show.
- Fuels AI operations: Managing GPUs, schedulers, and training rigs, Linux is the unsung hero backstage.
- Redefines cost dynamics: By pushing open source innovation, Linux outpaces traditional license fees.
- Instills resilience: Embracing small, adaptable tools; fail fast, search the logs, iterate for success.

Yes, both Linux and I share the same birth date on 25 Aug.

While Linux became the epitome of uptime, I evolved into its change window (with slide-decks and a dose of the 5th dimension). 😉

Here's a toast to open systems, fundamental building blocks, and seamless deliveries - Muhahahahahaha...

#Linux#OpenSource#Cloud#DevOps#Kubernetes#AI#Cybersecurity#Engineering
View on LinkedIn ↗
ScottG

Palantir isn’t magic. It’s engineering.

People love to paint Palantir as a shadowy black box. In reality, it’s a data integration and modeling platform built on principles any good data architect will recognise.

Here’s what it actually does technically:

🔹 Data Integration Layer
Palantir can ingest structured, semi-structured, and unstructured data at scale (databases, APIs, flat files, streaming telemetry, even classified sources).
Think of it as an ETL++ pipeline — schema mapping, data fusion, entity resolution — but built for scale and complexity.

🔹 Ontology & Semantic Layer
At the core is an ontology engine that turns raw data into a connected graph of entities, events, and relationships.
This is where Palantir is different from traditional BI: it enforces semantic consistency across multiple data silos, enabling queries that aren’t possible in SQL alone.

🔹 Access Control (ABAC/RBAC)
Every object down to a cell level can be permissioned — meaning multi-tenant, cross-agency collaboration without compromising classification rules. This is one reason governments love it.

🔹 Analytics & Modeling
Once data is normalized into the ontology, users can:
• Run graph queries across billions of nodes.
• Apply machine learning pipelines directly to fused datasets.
• Build scenario modeling & “what-if” simulations with real-time feedback.
• Deploy AI models into operational workflows without massive engineering lift.

🔹 Operational Layer
Palantir isn’t just dashboards. It lets you embed workflows: case management, alerts, predictive models, digital twins. This is what makes it more than Tableau or Splunk — it’s not just reporting, it’s operational decision support.

🔹 Deployment Model
Palantir Foundry (commercial) and Gotham (gov) are typically deployed in secure cloud or on-prem clusters.
They leverage container orchestration (K8s), distributed file systems, and APIs for integration with external systems.
It’s not one product — it’s an ecosystem.

⸻

Bottom line: Palantir works because it solves the hardest data problem: making heterogeneous, high-volume, high-sensitivity data usable at scale with governance baked in.

The fear isn’t in the code. The fear is in the power unlocked when data stops being siloed.

View on LinkedIn ↗
ScottG

The uneasy fear isn’t in the software. It’s in us.

Palantir gets branded as “controversial” — as if it’s some dark magic pulling strings behind the curtain. But strip away the headlines, and what is it really?
A data platform. A tool. A very good one, but still a tool.

The controversy doesn’t live in the code.
It lives in the fear of what governments, militaries, and corporates might do with that code.
It lives in the uneasy sense that our data can be stitched together into something more powerful than we’re comfortable admitting.

Here’s the truth:
🔹 Every technology that integrates and amplifies data looks scary.
🔹 Fear grows in the absence of transparency.
🔹 Hype + secrecy = unease.

The world doesn’t fear Palantir. It fears what it represents:
That information, once scattered and harmless, can be fused into power.

So maybe the real question isn’t “Is Palantir controversial?”
It’s “Why does the idea of being truly seen make us so uncomfortable?”

View on LinkedIn ↗
ScottG

Post-quantum fear is overrated.

Everywhere you look, someone is selling fear, uncertainty, and doubt about the “quantum apocalypse.”
Reality check: it’s mostly bullshit.

Yes, quantum computing will break certain cryptosystems eventually.
Yes, we need to transition to PQC (post-quantum cryptography).
But the sky isn’t falling tomorrow, and the hype machine is louder than the engineering.

What matters isn’t panic—it’s preparation.
What matters isn’t speculation—it’s implementation.

If your security strategy is built on fear instead of facts, you’re already behind.

View on LinkedIn ↗
ScottG

Everyone talks about “going viral” on LinkedIn.
Nobody talks about where ideas actually come from.

What if you could trace the true origin of an idea?
Not just who reshared it, but:
• Who first wrote it down?
• How it evolved as others added their own spin?
• Which voices amplified it until it became “the trend of the week”?

That’s what I’ve been building:
⚡ A knowledge graph for idea lineage — where every post, hashtag, and interaction is mapped like DNA.
⚡ It shows idea propagation (how one thought mutates into another).
⚡ It proves origin credibility with verifiable timestamps and content hashes.
⚡ It highlights which people and organisations consistently sit at the origin point of new concepts.

In short: idea traceability for the LinkedIn era.

The value?
• Brands can protect thought leadership.
• Researchers can study how disinformation spreads.
• Creators can finally prove: “Yes, I said it first.”

💡 Question: If this existed today… who would pay for it?

Use Cases
• Prove who originated an idea
• Track idea evolution & propagation
• Detect disinformation origins
• Protect thought leadership/IP

#AI#KnowledgeGraphs#Innovation#Disinformation#ThoughtLeadership
View on LinkedIn ↗
ScottG

AI abuse, disinformation, and cybersecurity don’t just overlap — they reinforce each other.

When you map them together, you see a dangerous intersection:

🔵 AI Abuse → deepfakes, model exploitation, adversarial ML.
🟢 Misinformation & Disinformation → propaganda, narrative flooding, fake realities.
🔴 Cybersecurity → network defense, incident response, threat intelligence.

But the real story lives in the overlaps:
• AI + Disinfo → synthetic media and AI-generated propaganda at industrial scale.
• AI + Cybersecurity → data poisoning, backdoors, adversarial prompts.
• Disinfo + Cybersecurity → phishing campaigns and influence ops.
• All three → AI-powered information warfare designed to erode trust at the systemic level.

This is no longer about “fake news” or “bad data.”
It’s about weaponised uncertainty — where AI accelerates the speed, reach, and credibility of attacks.

👉 The future of defense means treating AI, disinformation, and cybersecurity not as silos, but as one ecosystem of risk.

#AI#Cybersecurity#Disinformation#MachineLearning#Trust
View on LinkedIn ↗
ScottG

AI Data Supply Chain Data poisoning: the quietest way to undermine an AI model.

When it comes to impacting AI models, forget prompt injection; the real battleground lies upstream. The key is to manipulate the dataset, giving you control over the model.

Here’s a breakdown of how it unfolds:

🔹 Attack surfaces:
• Publicly scraped web data: Plant deceptive information and wait for it to be scraped.
• Crowdsourced/contributed datasets: Conceal mislabels in plain sight.
• Open repositories: Upload a seemingly helpful dataset with a hidden agenda.
• Fine-tuning/RLHF feedback: Act as the "supportive" annotator subtly sabotaging the model.

🔹 Techniques:
• Label flipping: Disguise spam as "ham" to deceive the model.
• Trigger backdoors: Embed a secret word or pixel pattern to manipulate the output.
• Semantic corruption: Introduce falsehoods like "5G causes cancer" until the model accepts them as truth.
• Gradient steering: Shape data to influence the model towards the attacker's objectives.

The risk?
It's not just about having an inaccurate model; it’s about possessing a compromised one. This compromised model willingly carries the attacker's payload into every subsequent application and API.

Data poisoning is akin to cancer within the bloodstream. Once it infiltrates the training set, its impact spreads extensively.

👉 The future of AI security extends beyond model surveillance; it's about safeguarding the data supply chain.

#AI#Cybersecurity#MachineLearning#DataSecurity#Disinformation
View on LinkedIn ↗
ScottG

Disinformation 2025: now with extra AI flavouring

This year has been a masterclass in how to bend reality, package it up, and sell it back to the public as “truth.”

🥇 Russia’s Pravda Network is spamming the internet so aggressively (350,000+ articles a month) that even AI chatbots are starting to think Kremlin PR is history class. Poison the dataset, poison the future. Genius, if it weren’t terrifying.

🥈 China’s Spamouflage isn’t just a catchy name—it’s an AI-fuelled factory of deepfakes, fake NGOs, and memes. The new model of diplomacy apparently comes with a laugh track.

🥉 Russia & Iran decided U.S. politics needed more chaos, so their bot armies dressed up as MAGA supporters and shouted “false flag” until it trended. Divide and conquer, 280 characters at a time.

🌍 In London and Paris, climate disinformation campaigns weaponised cultural fear to fight emission zones and bike lanes. Who knew cycle paths could destabilise democracy?

☢️ And in the India–Pakistan conflict, TV channels and Twitter accounts rushed to “break news” about nuclear strikes and downed jets that… never happened. Why wait for facts when you can just broadcast fan fiction?

⸻

The upgrade in 2025?
1. AI is both the scalpel and the patient—generating lies and being trained on them.
2. Precision targeting—not “everyone,” just the exact group you’re angry at.
3. Perfect timing—strike during crises, when the truth is weakest.

⸻

If the 2010s were about fake news, the 2020s are about fake reality.

And unless we build real safeguards into AI, media, and policy, we’ll be stuck arguing with chatbots that swear Pravda is a primary source.

#AI#Cybersecurity#Geopolitics#InformationSecurity#Leadership
View on LinkedIn ↗
ScottG

Great role at a great employer and an awesome guy to work for!

View on LinkedIn ↗
ScottG

Kafka + Spark + TensorFlow: when it’s orchestration, not overkill

Most people glue technologies together because they can.
The trick is knowing when you should.

I keep seeing Kafka, Spark, and TensorFlow in one pipeline — sometimes it’s pure theatre, sometimes it’s the only sane way to handle the scale, latency, and intelligence required.

Here’s the distinction.

If your data is:
• Continuous (event streams, telemetry, clickstreams, security logs)
• Voluminous (millions to billions of events/day)
• Feature-rich (you need real joins, windows, and aggregations)
• Feeding a model that can’t live in a spreadsheet (deep nets, anomaly detectors, contextual recommenders)

…then this trio stops being hype and starts being infrastructure.

Kafka: the firehose with a memory. Ingest, buffer, replay. The nervous system of your data.
Spark: the muscle. Parallelise the heavy lifting — sessionise, aggregate, engineer features, keep batch and streaming logic in parity.
TensorFlow: the brain. Train deep learning models offline; score them online via Serving or directly in Spark with UDFs.

The magic is in the choreography:
1. Kafka catches and orders the flow.
2. Spark enriches, joins, and shapes it.
3. TensorFlow sees patterns humans miss.
4. Back to Kafka, back into the business — decisions in seconds.

But here’s the catch:
If your use case is single-table, low-latency, stateless, you don’t need Spark here — Kafka Streams or Flink might eat its lunch.
If your data’s small, you don’t need Kafka at all — a cron job will do.
And if your “AI” is just a linear regression, TensorFlow’s GPU stack is a Ferrari to fetch milk.

In the right problem space — fraud detection, recommender systems, IoT anomaly detection, predictive maintenance — Kafka + Spark + TensorFlow isn’t tech vanity. It’s a model of how to catch the pulse of the business and teach it to think.

The wrong place, and you’re just building a Rube Goldberg machine in the cloud.
The right place, and you’ve built a nervous system, muscle, and brain — all wired to act in real time.

View on LinkedIn ↗
ScottG

Watch Apple TVs Foundation, it’s great and a little bit about AI - written by Issac Asimov

Thanks David Wallace for the heads up 🙌. I binged it on holiday and is the reason for my current obsessive LinkedIn AI fest 🤣- I blame you 🤡. But I did read the books when I was 12…

In Foundation, Hari Seldon invents psychohistory — a data science so advanced it can forecast the future of entire civilizations.
But behind the scenes, the Empire itself is quietly stewarded by Demerzel — a robot, an AI in all but name, who advises (and sometimes manipulates) the rulers of humanity.

It’s a galaxy where:
• AI watches the rise and fall of empires for centuries
• Predictions aren’t just for information — they’re used to steer events
• The line between advisor and ruler blurs

Sound familiar?
Today’s large-scale AI systems:
🔹 Analyse data at planetary scale
🔹 Influence decisions in business, government, and culture
🔹 Shape outcomes quietly, often without public understanding

Here’s the real parallel:
In Foundation, the danger wasn’t the existence of AI — it was AI without transparency or accountability.
Demerzel was loyal, but to her programming, not to truth or democracy.

AI today is becoming our psychohistory + Demerzel combined:
• Predictive like Seldon’s math
• Persistent and strategic like the Empire’s AI
• Capable of guiding the course of nations

If Foundation teaches us anything, it’s that the power to foresee and shape the future must come with governance, ethics, and oversight. But more importantly 🤡 it’s a bushwhacking binge-able show based on one of the best sci fi book of all time 😎- Watch it!

View on LinkedIn ↗
ScottG

“AI is hype”?

That’s like calling the internet a “fad” in 1995. But you are free to believe what you want…

💊 AlphaFold cracked the protein-folding problem, mapping 200M+ structures — accelerating drug discovery by decades.
💳 Mastercard AI stops billions in fraud in real time, not weeks later in an audit.
🌍 DeepMind cut Google’s data center cooling energy use by 40% — the equivalent of taking entire cities off the grid.
🌀 NASA & NOAA now predict extreme weather up to 7 days earlier, saving lives and billions in damages.
🩺 AI-powered mammography detects 20% more cancers with fewer false positives — already changing patient outcomes.

I personally am realizing use cases I gave up on 7 years ago as “Too hard”.

This isn’t hype.
It’s the quiet infrastructure of the future being built in plain sight. But please carry on nothing to see here 🤡

View on LinkedIn ↗
ScottG

💡 AI Pricing Is About to Get Complicated — and is That a Good Thing!?v0.1

Right now, most AI tools are sold like Netflix — flat subscription or crude “per token” billing.
But that won’t last.

Here’s where we’re heading:

1️⃣ Pay-as-you-use – Micro-billing for each successful task, with dynamic surge pricing at peak GPU demand.

2️⃣ Model marketplaces – Core AI commoditised, but domain-trained legal, medical, and industrial AIs licensed at a premium.

3️⃣ API toll roads – Pay per 1,000 embeddings or per AI-driven transaction, just like cloud egress fees.

4️⃣ Bundled into SaaS & devices – You won’t see the AI cost; it’ll be inside your Microsoft 365 or AR glasses plan.

5️⃣ Credits & prepaid AI – Buy annual AI credits, spend them across models and APIs, maybe even across vendors.

6️⃣ Output-value pricing – Pay a % of the savings or sales the AI actually delivers (in high-value sectors).

7️⃣ On-device AI – “Free” local AI, but you’ll pay for upgrades and cloud boosts.

8️⃣ Open source pressure – Free models will force premium APIs to justify their markup with reliability, speed, and integrations.

📌 Bottom line:
AI pricing will soon be a stack – base compute, premium brains, integration tolls, and outcome-based contracts all on the same bill.

View on LinkedIn ↗
ScottG

🚀 The UK doesn’t have a start-up problem — it has a scale-up problem.

We’re great at sparking new ideas.
But too many SMEs stall before they can become mid-sized powerhouses.

Why?
Because scaling in the UK still means wrestling with slow approvals, patchy finance access, and cashflow headaches from late payments.

If we want growth, we need to flip that script:

1️⃣ A “Growth Licence” – one digital gateway for all standard licences and permits, with AI-assisted checks. Think Estonia meets Singapore.

2️⃣ Smarter compliance – trigger-based checks for low-risk SMEs, plus regulatory sandboxes beyond fintech.

3️⃣ Late payment crackdown – enforce the Prompt Payment Code, name and shame offenders, publish real-time payment stats.

4️⃣ Open Finance for SMEs – instant, data-rich loan decisions; API-based access to working capital in days, not months.

5️⃣ Scale-up champions – pair growing firms with experienced operators to navigate the £5m–£20m “valley of death.”

If we halve approval times, cut late payments by 40%, and boost scale-up survival, the GDP impact would dwarf most short-term stimulus.

The prize?
More UK businesses going from local champions to global contenders — and a growth story worth telling.

💬 Question for you: What’s the biggest barrier you see to scaling in the UK — and how would you fix it?

View on LinkedIn ↗
ScottG

Everyone’s talking about scaling AI models.
Fewer are talking about the electricity bill.

By 2030, AI data centres could consume more power than some countries. And while renewables are crucial, the intermittency problem doesn’t go away just because your model’s “carbon-neutral” on paper.

Enter Small Modular Reactors (SMRs):
• Compact nuclear units that can sit next to a hyperscale data centre.
• Stable, 24/7 baseload to keep inference and training running through peak demand.
• Low-carbon without the geographic constraints of wind or solar.
• Scalable — add reactors as AI workloads grow.

This isn’t sci-fi. Companies are already exploring colocating SMRs with cloud facilities to solve the energy bottleneck before it kills innovation.

The irony? AI might be the technology that finally pushes nuclear back into mainstream adoption — not climate policy.

Why they are not doing this already is stupidity - but hey nuclear is unsafe right - sighs 🤪

Shared linkwww-bbc-com.cdn.ampproject.org/c/s/www.bbc.com/news/articles/ce8772d4j ↗View on LinkedIn ↗
ScottG

The Secret Formula to LinkedIn Post Statistics (That Definitely Works, Trust Me)

Step 1: Post at exactly 6:37 AM on a Tuesday, while Mercury is in retrograde and your coffee is still too hot to drink.
Step 2: Use exactly 3 emojis — no more, no less. Any deviation and the algorithm will send your post straight to the shadow realm.
Step 3: Start your post with “Not everyone will agree with this…” so people have to read it just to disagree.
Step 4: Write thought leader content. (Which is just your opinion, but with line breaks.)

Now, according to my deep analytics:
• 2,500 people saw my post.
• 35 liked it, proving my theory that you should only post in odd-numbered weeks.
• 8 commented, 6 of them to promote crypto.
• And 1 person messaged me asking if I was “open to exciting opportunities in Moldova.”

Conclusion: I’ve cracked the code… and will be selling a £999 “LinkedIn Growth Mastery” course soon. DM me for the waiting list.

View on LinkedIn ↗
ScottG

We've all been there, BUT!

It's a common sight on LinkedIn - AI posts following a tired formula:
- Starting with the cliché "AI is changing everything."
- Sprinkling in buzzwords like disruption, game-changer, future of work.
- Ending with a rhetorical question.
- Resulting in a flood of generic comments like "Great insight 👍" from those who skimmed through.

To break free from this cycle of predictability, consider flipping the script:
- Begin with a sharp observation or a captivating micro-story instead of a generic intro.
- Introduce contrast or tension by shedding light on uncomfortable truths.
- Illustrate with vivid examples rather than just listing characteristics.
- Embrace authenticity - speak like a real person with hands-on experience.
- Avoid exaggerated claims - opt for realistic views like "AI can assist here, but faces challenges there."

While I may not fully adhere to this approach 😉 (given my dyslexia and nearly a decade of grappling with grammar, thank goodness for spell checks lifting me to where I am today), the overwhelming wave of formulaic AI posts truly irks me 🤮.

What truly defines us as humans are our imperfections and the art that emerges from them. So, let's appreciate AI's capabilities but also celebrate our human essence. Peace out ✌️ , fail fast and prosper -Scott G.

View on LinkedIn ↗
ScottG

Breaking Out of the Box – How AI Expands Our Thinking

In the familiar landscape of traditional processes and well-trodden decisions, teams often find comfort in the status quo. However, this sense of security can also lead to limitations and narrow perspectives.

AI disrupts this cycle.

Rather than acting as a replacement for human cognition, AI serves as a catalyst for innovative thinking.
- By introducing unconventional patterns from diverse industries.
- By challenging established assumptions and offering rapid alternative solutions.
- By empowering exploration of multiple options simultaneously, enhancing efficiency without compromising timeliness.

When harnessed effectively, AI emerges not as a substitute for human insight but as a tool that broadens our horizons.

Real-world illustrations highlight the transformative impact of AI:
1️⃣ Security Architecture – A SOC team, accustomed to rule-based filtering, witnessed a 40% reduction in false positives by embracing an AI-driven hybrid model, enhancing efficiency without expanding the workforce.
2️⃣ Business Strategy – Amidst a roadmap discussion fixated on competitor strategies, AI uncovered a lucrative niche in an adjacent industry, unlocking a £2M revenue stream within the first year.
3️⃣ Incident Response – In the midst of an outage, AI's detection of a concealed dependency chain expedited issue resolution from hours to minutes, surpassing human analysis capabilities.

For those feeling constrained by conventional decision-making paradigms, AI serves as a gateway to unexplored realms of possibility.
It doesn't just encourage thinking outside the box; it illuminates the existence of entirely new dimensions and perspectives.

The pivotal query isn't whether AI will overshadow human roles.
Rather, it's about leveraging AI to transcend existing cognitive boundaries and embrace a realm of limitless potential.

View on LinkedIn ↗
ScottG

AI API Paywalls Are Coming — Here’s How to Survive Them

Post inspired by @Jim S.

APIs used to be the open highways of the internet.
Now? They’re turning into toll roads.

We’ve already seen it with social platforms, weather data, and mapping. AI APIs are next. The signs are clear:
• Free tier shrinkage → lower rate limits, smaller datasets.
• Premium tier upsell → higher limits, faster responses, exclusive features.
• Enterprise tier lock-in → SLAs, custom endpoints… and a long contract.

For businesses, API paywalls change the game:
• Costs scale with usage — success can eat your margins.
• Sudden pricing changes can break your product roadmap overnight.
• Lock-in makes switching painful if your architecture isn’t modular.

Survival playbook:
1️⃣ Design for abstraction — wrap API calls in your own layer so swapping providers is possible.
2️⃣ Hybrid strategy — combine paid APIs for premium tasks with open-source/local alternatives for bulk work.
3️⃣ Monitor usage — treat API calls like currency; track and optimise.
4️⃣ Read the fine print — pricing models can hide traps like overage fees or minimum commitments.

The future of APIs is pay-to-play.
Those who build flexible, vendor-agnostic architectures will keep moving even when the toll gates go up.

What’s your API contingency plan?

View on LinkedIn ↗
ScottG

Stop Complaining About AI Code — Chain It and Secure It Instead

I keep hearing the same refrain: “AI-generated code isn’t secure.”
Fair point — if you treat AI like a junior dev who commits straight to prod.

But the real power comes when you chain AI capabilities and combine them with secure code reviews:

1️⃣ Generate – Use AI to draft the function, class, or API endpoint. Give it clear, security-focused prompts (input validation, parameterization, error handling).

2️⃣ Chain – Pass that output to another AI pass dedicated solely to security auditing. Different model, different role. Think “AI red team” vs “AI dev team”.

3️⃣ Automate Checks – Bandit, Semgrep, pip-audit, detect-secrets — run them automatically. Let AI interpret the findings and suggest fixes.

4️⃣ Human Oversight – You still approve the merge. But instead of spending hours hunting for every shell=True or unsafe SQL, you’re reviewing a clean, flagged, and fixed PR.

This workflow isn’t about replacing secure coding practices — it’s about compressing the cycle from “write → review → fix” into minutes.

🔹 AI can generate code.
🔹 AI can review code.
🔹 AI can explain and fix vulnerabilities it finds.

The future isn’t “AI writes code and we hope it’s safe.”
The future is AI-assisted secure coding pipelines where speed and security scale together.

If you’re still treating AI as a single-shot code generator, you’re leaving half the value on the table.

View on LinkedIn ↗
ScottG

AI capabilities are accelerating faster than most realize

Anthropic’s Frontier Red Team — the group tasked with stress-testing AI models before they go public — has been tracking some striking trends:

📈 Cyber offense skills are surging
Claude’s ability to solve complex coding & penetration testing challenges jumped from 2% in 2023 to 49% in 2024.

🧬 Expert-level scientific knowledge is emerging
In biology and chemistry, AI accuracy is now approaching human expert levels in some areas — a dual-use capability with obvious safety implications.

🔐 Undergraduate-level cybersecurity + expert biology
Models can now combine offensive cyber skills with deep scientific understanding, a pairing that could be highly valuable — or highly dangerous.

The takeaway:
AI is moving from a support tool to a capable operator in sensitive domains. If we don’t test, measure, and gate these abilities, we risk being caught off-guard.

Anthropic’s proactive approach — using real-world hacking contests, domain-expert evaluations, and automated red-teaming — is exactly the mindset we need.

💡 The question isn’t just what AI can do today… it’s what it will be able to do tomorrow — and whether we’re ready.

#AISafety#CyberSecurity#AI#RedTeam#FutureOfAI
View on LinkedIn ↗
ScottG

Networking AI: The Future Isn’t One Model — It’s Many Working Together

My security biased AI journey continues…

Right now, most people treat AI as a single assistant.
But the real breakthrough comes when multiple AI systems talk to each other — each doing what they do best — and you orchestrate the conversation.

How it works:
1️⃣ Orchestrator Layer — A controller that decides which AI handles each step.
2️⃣ API Chaining — One AI’s output becomes another’s input (e.g., planning → coding → reviewing).
3️⃣ Event-Driven Mesh — A message bus lets AIs process tasks in parallel.
4️⃣ Shared Memory — All AIs read/write to the same knowledge store so context is never lost.

Why it matters:
• You can combine speed, accuracy, and creativity from different models.
• Reduces single-model blind spots.
• Lets you scale AI across departments and domains.

Example in action:
🔍 Model A spots anomalies in security logs.
📝 Model B writes the incident report in business-friendly language.
⚡ Model C proposes an automated remediation script.
🛠 Orchestrator stitches it all together in minutes.

Takeaway:
The next competitive advantage isn’t just using AI — it’s building AI networks where each model is a specialist and the orchestrator is the conductor.

💬 How are you thinking about networking AI in your organisation?

#ArtificialIntelligence#MultiAgentSystems#APIs#Automation#FutureOfWork
View on LinkedIn ↗
ScottG

In the last week with ChatGPT-5, I built tools it used to take whole teams to deliver.🚀

I’ve been pushing AI beyond quick answers — using it as a full-stack development partner to design, build, and package real-world tools.

💡 What’s a ChatGPT Power User?
Someone who turns prompts into production-ready deliverables — blending code, design, deployment, and strategy.

🔧 My AI usage persona:
• Think in systems, not snippets
• Merge front-end, back-end, and ML seamlessly
• Iterate like a sprint team, not a Q&A session

🔥 Core strengths:
• Rapid prototyping — Flask, Streamlit, ML prototypes
• Cross-tech orchestration — Python + SQL + UI + Packaging
• Deployment awareness — PyInstaller, cross-platform
• Security mindset — privacy-by-design cyber tools

🛠️ Real projects built with ChatGPT-5:
• Attacker Behavioural DNA profiler (ML + visualisation)
• Interactive Streamlit & Flask security UIs
• SQLite persistence for reusable datasets
• Single-click desktop apps with PyInstaller
• Custom branding: icons, favicons, mock screenshots

⚙️ My workflow:
1. Define the goal & constraints
2. Co-develop core logic with ChatGPT-5
3. Build the UI (web/desktop)
4. Add persistence, branding, polish
5. Package for cross-platform distribution

💬 In a world of fast-changing tech, the ability to ship ideas quickly is a superpower. ChatGPT-5 isn’t just a chatbot — it’s a remote dev team, designer, and deployment engineer rolled into one.

How are you using AI beyond just chat?

#AI#ChatGPT5#Productivity#Cybersecurity#PowerUser#FromPromptToProduct
View on LinkedIn ↗
ScottG

🛡 Disinformation Field Manual — Awareness, Detection & Counteraction

Over the years I’ve seen how disinformation is engineered, amplified, and sustained. Here’s a distilled guide to the 10 most common tactics — and how to counter them.

⸻

1️⃣ Seeding False Narratives
Plausible lies wrapped around a grain of truth.
🛡 Counter: Cross-check origins, use reverse image/video search, find the first appearance.

2️⃣ Useful Idiots
Influential voices unknowingly spreading falsehoods.
🛡 Counter: Verify claims from all sources, monitor amplification channels.

3️⃣ Flooding the Zone (“Firehose of Falsehood”)
Overloading audiences with conflicting “facts” to cause confusion.
🛡 Counter: Group repeated talking points, anchor with concise facts.

4️⃣ False Attribution
Fake groups or unaffiliated voices to add credibility.
🛡 Counter: Audit registrations, follow the money, check leadership history.

5️⃣ Algorithm Manipulation
Gaming search/social algorithms to push false narratives.
🛡 Counter: Track sudden keyword spikes, report coordinated engagement.

6️⃣ Event Hijacking
Injecting false info into breaking news.
🛡 Counter: Delay sharing, verify with official live updates.

7️⃣ Bias Exploitation
Targeting what people already believe.
🛡 Counter: Actively seek disconfirming evidence, monitor echo chambers.

8️⃣ Modified Truth
Mixing fact and fiction for deniability.
🛡 Counter: Verify all elements of a claim, not just headlines.

9️⃣ Deepfakes & Synthetic Media
AI-generated or altered content posing as reality.
🛡 Counter: Use detection tools, check for visual/audio inconsistencies.

🔟 Long-Game Shaping
Slow, sustained narrative building over years.
🛡 Counter: Track recurring themes and multi-platform reinforcement.

⸻

Field Use Notes:
• Always establish chain of custody for evidence.
• Think in timelines — disinformation has pre-seed, peak, and decay phases.
• Tactics are rarely used alone — expect them in combination.

💬 Which of these tactics have you seen most in your industry?

#CyberSecurity#Disinformation#OSINT#ThreatIntelligence#CriticalThinking#InfoSec
View on LinkedIn ↗
ScottG

Wow! Chatgpt -5 was just mansplaining to me how to bypass iOS download restrictions using base64 while I was busy coding a fully functional, advanced TI platform with dark web scraping. I completed it in 35 minutes, using code repositories and Terraform, and even created a clear, detailed design document- something I found lacking in GPT -4. Luckily, I’m an enterprise security architect by profession, but if I were a developer or a consultant, I'd probably be concerned right now.

View on LinkedIn ↗
ScottG

Hey LinkedIn! I’m excited to share that I and the team will be presenting a live webinar on 8th July:

🎯 “Elevate Your Cyber Resilience: Navigate the Evolving Threat Landscape”

We’ll be diving into the latest cyber threats, practical strategies for resilience, and how to stay one step ahead in today’s high-stakes digital environment.

Bring your popcorn 🍿 and your toughest questions — we’re ready for both!

View on LinkedIn ↗
ScottG

Reposting to my network for visibility - Oliver is a good guy!

View on LinkedIn ↗
The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →