<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.3.3">Jekyll</generator><link href="https://kwm.me/feed.xml" rel="self" type="application/atom+xml" /><link href="https://kwm.me/" rel="alternate" type="text/html" /><updated>2026-08-15T16:40:04+00:00</updated><id>https://kwm.me/feed.xml</id><title type="html">KWM</title><subtitle>Cybersecurity, technology, very likely other surprise topics along the way.</subtitle><author><name>by Keith McCammon</name></author><entry><title type="html">Frontier AI models and regulatory capture</title><link href="https://kwm.me/posts/regulatory-capture-of-frontier-ai/" rel="alternate" type="text/html" title="Frontier AI models and regulatory capture" /><published>2026-06-26T00:00:00+00:00</published><updated>2026-06-26T00:00:00+00:00</updated><id>https://kwm.me/posts/regulatory-capture-of-frontier-ai</id><content type="html" xml:base="https://kwm.me/posts/regulatory-capture-of-frontier-ai/"><![CDATA[<p>Regulatory capture of frontier AI models would be an absolute gift to the ecosystem of companies blessed to use them. Here’s a <a href="https://steve-yegge.medium.com/the-flat-curve-society-36c8b01eb33b">directly related prediction from Steve Yegge on June 18, 2026</a>:</p>

<blockquote>
  <p>The AI race isn’t going to slow down, and AI will continue to grow exponentially in capability. Unfortunately, most of you aren’t going to see it progress anymore.</p>
</blockquote>

<blockquote>
  <p>I am now in the camp who believe that we are only at most two or three model generations away from AI finally being controlled like nuclear weapons. Only a few will have access to superintelligence above the classes of models we’re seeing this year. As far as I can tell, most Fortune 500 companies will either not have access at all, or it will be tightly controlled for only a small subset of the company. And it will be supervised.</p>
</blockquote>

<blockquote>
  <p>I think those with access to powerful frontier models will sell intelligence like a vending machine: You send them a software spec or a problem to solve, and their models implement it for you, on their servers, with your dollars.</p>
</blockquote>

<p>The AI labs are opposed to this today. To wit, here is <a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI’s GPT-5.6 announcement on June 26, 2026</a>:</p>

<blockquote>
  <p>We believe in broad access, and we plan to make GPT‑5.6 Sol, Terra, and Luna generally available in the coming weeks. As part of our ongoing engagement with the U.S. government, we previewed our plans and the models’ capabilities ahead of today’s launch. At their request, we are starting with a limited preview for a small group of trusted partners whose participation has been shared with the government, before releasing more broadly. During this preview, we will continue testing and coordinating closely with partners as we work toward broader availability. We don’t believe this kind of government access process should become the long-term default. It keeps the best tools from users, developers, enterprises, cyber defenders, and global partners who need them. We are taking this short-term step because we believe it is the strongest path to broader availability in the coming weeks, while we work with the Administration to develop the cyber Executive Order framework and a repeatable process for future model releases.</p>
</blockquote>

<p>It’s interesting to game out how they might reconsider, should the frontier labs find themselves in a situation where broad B2B adoption is no longer viable (or, is simply <em>harder</em> than leaning into an intelligence cartel).</p>]]></content><author><name>by Keith McCammon</name></author><category term="Posts" /><summary type="html"><![CDATA[Regulatory capture of frontier AI models would be an absolute gift to the ecosystem of companies blessed to use them. Here’s a directly related prediction from Steve Yegge on June 18, 2026:]]></summary></entry><entry><title type="html">Every AI Subscription Is a Ticking Time Bomb for Enterprise</title><link href="https://kwm.me/links/ai-ticking-time-bomb/" rel="alternate" type="text/html" title="Every AI Subscription Is a Ticking Time Bomb for Enterprise" /><published>2026-05-19T00:00:00+00:00</published><updated>2026-05-19T00:00:00+00:00</updated><id>https://kwm.me/links/ai-ticking-time-bomb</id><content type="html" xml:base="https://kwm.me/links/ai-ticking-time-bomb/"><![CDATA[<p>For several years now, the pendulum has continued its swing towards “more AI, at any cost”, and it now feels like it has reached its apex.</p>

<blockquote>
  <p>OpenAI, Anthropic, Google, and the rest are running an industry-wide loss-leader program at a scale that has no precedent. They are selling enterprises filet mignon at gas station hot dog prices and calling it a business model. The gap between what your company pays for AI subscriptions and what it actually costs to serve those seats is not a rounding error. It is a gulf. And every organization that has built workflows, products, or entire business units on top of these subsidized prices is standing right on the edge of it. ❡ This should be front of mind for every CTO, CFO, and head of operations reading this. Because when the pricing corrects, and it will, the companies that treated AI as a permanently cheap utility are going to wake up to bills that make their current SaaS spend look quaint.</p>
</blockquote>]]></content><author><name>by Keith McCammon</name></author><category term="Links" /><summary type="html"><![CDATA[For several years now, the pendulum has continued its swing towards “more AI, at any cost”, and it now feels like it has reached its apex.]]></summary></entry><entry><title type="html">Assorted links 2026-05-19</title><link href="https://kwm.me/notes/assorted-links-2026-05-19/" rel="alternate" type="text/html" title="Assorted links 2026-05-19" /><published>2026-05-19T00:00:00+00:00</published><updated>2026-05-19T00:00:00+00:00</updated><id>https://kwm.me/notes/assorted-links-2026-05-19</id><content type="html" xml:base="https://kwm.me/notes/assorted-links-2026-05-19/"><![CDATA[<ol>
  <li>
    <p><a href="https://joshuasaxe181906.substack.com/p/exploits-dont-cause-cyberattacks">Exploits don’t cause cyberattacks: On thinking clearly about frontier AI advances and cyber conflict</a> - “[M]ost of today’s attacker constituencies can currently achieve most of their desired outcomes using traditional means: simple phishing, credential stuffing, exploitation of known CVEs, etc. These constituencies aren’t likely to explode into hockey-stick adoption of AI vulnerability research tools. ❡ This should discipline our thinking about Mythos generating a discontinuous volume of cyberattacks, because, again, most attacker constituencies just aren’t blocked by vulnerability research for most of their workflows.”</p>
  </li>
  <li>
    <p><a href="https://www.provos.org/p/finding-zero-days-with-any-model/">Finding Zero-Days with Any Model: Vulnerability discovery is an orchestration problem, not a frontier-model problem.</a> - “[W]ell-resourced adversaries already use orchestrated workflows to hunt for zero-days at scale. They operate free from vendor usage policies, AUP friction during legitimate research, API rate limits on multi-hour runs, and curated access lists for embargoed frontier models. The seven-step refusal during severity assessment is exactly the asymmetry at issue: a defender doing legitimate work hit friction that a well-resourced adversary using uncensored open-weight models would not.”</p>
  </li>
</ol>]]></content><author><name>by Keith McCammon</name></author><category term="Notes" /><summary type="html"><![CDATA[Exploits don’t cause cyberattacks: On thinking clearly about frontier AI advances and cyber conflict - “[M]ost of today’s attacker constituencies can currently achieve most of their desired outcomes using traditional means: simple phishing, credential stuffing, exploitation of known CVEs, etc. These constituencies aren’t likely to explode into hockey-stick adoption of AI vulnerability research tools. ❡ This should discipline our thinking about Mythos generating a discontinuous volume of cyberattacks, because, again, most attacker constituencies just aren’t blocked by vulnerability research for most of their workflows.”]]></summary></entry><entry><title type="html">Security Operations Center (SOC) outcomes in the age of AI</title><link href="https://kwm.me/posts/agentic-soc-outcomes/" rel="alternate" type="text/html" title="Security Operations Center (SOC) outcomes in the age of AI" /><published>2026-05-12T00:00:00+00:00</published><updated>2026-05-12T00:00:00+00:00</updated><id>https://kwm.me/posts/agentic-soc-outcomes</id><content type="html" xml:base="https://kwm.me/posts/agentic-soc-outcomes/"><![CDATA[<p>For all the hype around AI and agentic Security Operations Center (SOC) solutions, what truly matters comes down to two questions:</p>

<ul>
  <li>What threats can you detect today that you couldn’t before?</li>
  <li>What existing threats can you now detect consistently and provably faster?</li>
</ul>

<p>There’s no shortage of benefits to leveraging AI across a cybersecurity program, and it’s easy to get lost in everything AI can do. But job number one for any SOC is detecting and responding to cybersecurity threats, and it doesn’t matter much how this is achieved (i.e., I don’t care if it’s humans or robots), so long as it’s effective.</p>

<p>Whether you’re a SOC manager, analyst, or buyer evaluating AI or agentic SOC solutions, working backwards from what your SOC is already supposed to deliver cuts through virtually all of the AI-related hype and noise.</p>]]></content><author><name>by Keith McCammon</name></author><category term="Posts" /><summary type="html"><![CDATA[For all the hype around AI and agentic Security Operations Center (SOC) solutions, what truly matters comes down to two questions:]]></summary></entry><entry><title type="html">Exploits and malware are still subject to the laws of physics</title><link href="https://kwm.me/posts/malware-subject-to-the-laws-of-physics/" rel="alternate" type="text/html" title="Exploits and malware are still subject to the laws of physics" /><published>2026-05-08T00:00:00+00:00</published><updated>2026-05-08T00:00:00+00:00</updated><id>https://kwm.me/posts/malware-subject-to-the-laws-of-physics</id><content type="html" xml:base="https://kwm.me/posts/malware-subject-to-the-laws-of-physics/"><![CDATA[<p><em>Why AI-powered vulnerability discovery and software exploitation don’t change the fundamentals of durable defense.</em></p>

<p>AI is going to make it faster and easier to find vulnerabilities and exploit them. Many advanced models including <a href="https://red.anthropic.com/2026/mythos-preview/">Claude Mythos</a>, trained on code, CVEs, and exploitation tradecraft, will compress the time between vulnerability discovery and weaponization. This is real, and it deserves serious attention. But before we catastrophize, we should anchor to a few stubborn truths.</p>

<h2 id="weve-always-had-more-malware-than-detection-logic">We’ve always had more malware than detection logic</h2>

<p>Signature-based detection was always a losing race. Malware variants and malicious artifacts have outnumbered signatures for as long as both have existed. Behavioral detection improved the math considerably, and for organizations that invest in depth of coverage, it casts a net that most adversaries, human or AI-driven, will struggle to avoid. Still, the gap between what adversaries produce and what defenders detect has always been nonzero. AI widens this gap by lowering the cost for adversaries to scale the production side of the equation, but AI doesn’t fundamentally change its structure.</p>

<p>All software is subject to the laws of physics. An exploit has to be delivered, and if it lands, it has to be followed by additional, observable activities. An exploit may subvert a given control or suppress an expected behavior at a given stage of the attack chain, but it doesn’t exempt the target system from the constraints, controls, and observability built into the environment.</p>

<p>An exploit unlocks a door, but even chained exploits orchestrated by AI agents are not a skeleton key.</p>

<h2 id="what-defenders-who-are-winning-actually-do">What defenders who are winning actually do</h2>

<p>Organizations that are well-positioned today got there by making sound architectural decisions and disciplined operational choices:</p>

<p><strong>Minimize attack surface.</strong> Rather than trying to defend everything equally, force activity through a small number of well-understood, well-defended, carefully monitored pathways or chokepoints. Shape the battlespace in your favor.</p>

<p><strong>Implement zero trust and segmentation principles throughout.</strong> Require a combination of device and identity trust as a prerequisite for access, enforced at as many layers and as often as practical. An adversary who gains a foothold still has to make moves—segmentation and conditional access make movement impractical, or at minimum, noisy and observable.</p>

<p><strong>Use deception to backstop other defensive controls.</strong> Honeytokens, decoy assets, and deceptive infrastructure have two defining characteristics: legitimate users don’t trigger them, and they are exceptionally inexpensive to deploy. Any interaction is, by definition, suspicious. In a world of high alert volume and limited analyst time, that kind of signal is invaluable.</p>

<p><strong>Watch what’s left, and what’s most likely to be abused, like a hawk.</strong> The set of adversary techniques that appear in the majority of real-world intrusions is not large. From <a href="https://redcanary.com/threat-detection-report/">Red Canary’s 2026 Threat Detection Report</a>:</p>

<blockquote>
  <p>[O]ver the last five years, we’ve detected at least one of the 10 most prevalent techniques in 46 percent of all detections. Over the same time period, we detected at least one of the top 20 techniques in 63 percent of detections.</p>
</blockquote>

<p>The defenders who are winning have optimized for the set of prevalent techniques that almost all adversaries use, building detection coverage against it, investing in rapid investigation workflows, and standing up response capabilities that can act decisively when a threat is confirmed.</p>

<h2 id="the-volume-problem-is-real-but-also-solvable">The volume problem is real, but also solvable</h2>

<p>Attack volume will increase. There is no serious argument against that. More actors with access to more capable tools will generate more exploits and malware variants, more intrusion attempts, more noise.</p>

<p>Defenders who are well-positioned today will still be well-positioned tomorrow. Not because nothing is changing, but because the principles that make a defense durable—attack surface reduction, zero trust, high-fidelity signals, and behavioral detection—become considerably more important in the face of increased adversary volume, speed, and efficacy.</p>

<p>The clock has gotten faster. Time-to-detect, time-to-investigate, and time-to-respond all need to come down. AI agents and emerging automation are well suited for exactly this: triage, investigation acceleration, and response orchestration are tractable problems, and the tools are improving quickly.</p>

<p>AI is and will continue to change the nature of threats as we know them today. But I don’t believe it will change the fundamental structure of the problem for thoughtful defenders.</p>]]></content><author><name>by Keith McCammon</name></author><category term="Posts" /><summary type="html"><![CDATA[Why AI-powered vulnerability discovery and software exploitation don’t change the fundamentals of durable defense.]]></summary></entry><entry><title type="html">Introducing Atomic Scorecard: A test tracking tool for ATT&amp;amp;CK + Atomic Red Team</title><link href="https://kwm.me/posts/atomic-scorecard/" rel="alternate" type="text/html" title="Introducing Atomic Scorecard: A test tracking tool for ATT&amp;amp;CK + Atomic Red Team" /><published>2026-04-18T00:00:00+00:00</published><updated>2026-04-18T00:00:00+00:00</updated><id>https://kwm.me/posts/atomic-scorecard</id><content type="html" xml:base="https://kwm.me/posts/atomic-scorecard/"><![CDATA[<p><img src="https://kwm.me/assets/images/atomic-scorecard/atomic-scorecard.png" alt="alt" /></p>

<p>If you haven’t tested it, it doesn’t work. This foundational thesis drove the creation of <a href="https://atomicredteam.io">Atomic Red Team</a> and the concept of atomic testing for cybersecurity teams. One key lesson from its adoption: testing is more like exercise than an exam. Small, regular tests pay far larger dividends than annual or “big bang” red team engagements.</p>

<p>To encourage ongoing testing, I’ve long maintained a <a href="https://kwm.me/posts/mitre-attack-atomic-testing-tool">crude spreadsheet</a> for tracking, scoring, and measuring test outcomes. I’ve now converted it into a web-based tool.</p>

<p><strong>What is it?</strong></p>

<p>At its core, Atomic Scorecard is a simple system of record for atomic tests. Like Atomic Red Team, it uses MITRE ATT&amp;CK as the foundation, but it overlays industry threat intelligence, and naturally makes it easy to find atomic tests relevant to each technique.</p>

<p>No account is needed. There’s no database or other backend. None of your test data is stored.</p>

<p><strong>Intelligence-driven prioritization</strong></p>

<p>The most common ATT&amp;CK hangup is that it’s expansive and hard to know where to start. Few organizations have enough threat intelligence to know which techniques matter most. And even then, prevalence data is more reliable than first-party intel alone. Not all techniques are created equal, and from <a href="https://redcanary.com/threat-detection-report/">Red Canary’s 2026 Threat Detection Report</a>:</p>

<blockquote>
  <p>[A] relatively small number of techniques play a role in a disproportionately large number of detections . . . [O]ver the last five years, we’ve detected at least one of the 10 most prevalent techniques in 46 percent of all detections. Over the same time period, we detected at least one of the top 20 techniques in 63 percent of detections.</p>
</blockquote>

<p>By default, the tool’s technique rankings are drawn from Red Canary’s annual report, observed across thousands of companies of every size and industry. Also included are Mandiant’s top techniques, sub-techniques, and a complete M-Trends ATT&amp;CK appendix by tactic:</p>

<ul>
  <li><a href="https://atomicscorecard.com/?rank=red_canary_2026">Red Canary 2026 Threat Detection Report (default)</a></li>
  <li><a href="https://atomicscorecard.com/?rank=mandiant_2026_techniques">Mandiant M-Trends 2026 Top Techniques</a></li>
  <li><a href="https://atomicscorecard.com/?rank=mandiant_2026_subs">Mandiant M-Trends 2026 Top Sub-Techniques</a></li>
  <li><a href="https://atomicscorecard.com/?rank=mandiant_2026_complete">Mandiant M-Trends 2026 Complete ATT&amp;CK appendix (top techniques and sub-techniques for every ATT&amp;CK tactic)</a></li>
</ul>

<p>You can also upload custom rankings to reflect your organization’s specific threat landscape.</p>

<p><strong>Integration of ATT&amp;CK + Atomic Red Team</strong></p>

<p>The tool is built to move you from documentation to execution in seconds:</p>

<ul>
  <li>Every technique is linked directly to the official MITRE ATT&amp;CK documentation</li>
  <li>For any technique where an Atomic Red Team test exists, a clickable logo appears that takes you directly to tests that correspond to that technique</li>
</ul>

<p>I recommend using the <a href="https://www.atomicredteam.io/docs/invoke-atomicredteam">Invoke-AtomicRedTeam framework</a>, which makes test selection, execution, and optionally things like prerequisites and cleanup fast and easy.</p>

<p><strong>Tracking and reporting</strong></p>

<p>Testing is less impactful if you don’t record and measure the results. For every technique that you test, you can categorize test outcomes into one of four states:</p>

<ul>
  <li>Missed: The attack went completely unnoticed.</li>
  <li>Observed: You saw the telemetry, but no alert was triggered.</li>
  <li>Detected: You were alerted to the activity.</li>
  <li>Mitigated: The attack was blocked or interdicted by existing controls.</li>
</ul>

<p><img src="https://kwm.me/assets/images/atomic-scorecard/atomic-scorecard-test-outcomes.png" alt="alt" /></p>

<p>You can also add notes related to a given technique, since a simple status may not capture important context, or mark a technique as not applicable to your environment.</p>

<p>A simple dashboard at the top makes it easy to see your test coverage and outcomes.</p>

<p><img src="https://kwm.me/assets/images/atomic-scorecard/atomic-scorecard-scoring.png" alt="alt" /></p>

<p><strong>Flexibility and customization</strong></p>

<p><img src="https://kwm.me/assets/images/atomic-scorecard/atomic-scorecard-maintainer.png" alt="alt" class="align-right width-40pct" /></p>

<p>To ensure this tool stays relevant as ATT&amp;CK, Atomic Red Team, and your priorities evolve, the Maintainer tools allow you to update or customize:</p>

<ul>
  <li>ATT&amp;CK version</li>
  <li>Atomic Red Team coverage</li>
  <li>Technique ranking</li>
</ul>

<p>There’s also a simple JSON-based backup and restore capability. Export your entire project as a JSON structure at any time. When you’re ready to resume, just import the file and pick up exactly where you left off.</p>

<p><strong>Share your feedback</strong></p>

<p>If there’s something you’d like to see that isn’t included, something isn’t working, or if  you’d just like to send some feedback, you can reach me via email: kwm @ this domain.</p>

<p><strong>Ready to start testing? Give it a go at <a href="https://atomicscorecard.com">https://atomicscorecard.com</a></strong></p>]]></content><author><name>by Keith McCammon</name></author><category term="Posts" /><summary type="html"><![CDATA[]]></summary></entry><entry><title type="html">Customer discovery questions (or, better alternatives to “What keeps you up at night?”)</title><link href="https://kwm.me/posts/better-customer-questions/" rel="alternate" type="text/html" title="Customer discovery questions (or, better alternatives to “What keeps you up at night?”)" /><published>2026-04-09T00:00:00+00:00</published><updated>2026-04-09T00:00:00+00:00</updated><id>https://kwm.me/posts/better-customer-questions</id><content type="html" xml:base="https://kwm.me/posts/better-customer-questions/"><![CDATA[<p>Whether you’re a founder, in sales, an account manager, or in almost any other customer-facing role, the most valuable thing you can do is ask your customers questions, and learn what their goals, incentives, and measures look like.</p>

<p>This is a short list of questions I’ve found lead to substantive discussion (these are geared toward cybersecurity teams, but most are broadly applicable):</p>

<p><strong>Q: How is your team measured?</strong></p>

<p>What I’m listening for:</p>

<ul>
  <li>Objectives, ideally those that roll up and support the broader organization</li>
  <li>Cybersecurity maturity models or frameworks (NIST CSF, CMMC, C2M2, etc.)</li>
  <li>Compliance audits or certifications (SOC 2, ISO 27001, FedRAMP, etc.)</li>
  <li>Risk measures, commonly specific to realized risks (exposure or vulnerability management, third-party risk, etc.)</li>
  <li><a href="https://kwm.me/posts/incidents-measuring-cybersecurity-progress">Incident measures</a> related to detection, investigation, containment, and response</li>
  <li>Other basic operational measures, like tickets or cases</li>
</ul>

<p><strong>Q: Where do your incidents come from?</strong></p>

<p>This is a simple question, but sometimes it lands. If it’s helpful to follow with some elaboration, consider:</p>

<ul>
  <li><strong>Q: What controls are most useful in helping you identify higher severity incidents?</strong></li>
  <li><strong>Q: What data or tools do you find most useful for investigation? Response?</strong></li>
</ul>

<p>These can lead to useful insights related to control effectiveness, operational maturity, and incident management. A good organization can tell you how many incidents they have; a great team can speak to trends related to root cause, severity, cost, mean time to detect/respond, and more. Teams that are exceptional at incident management will use incidents as a <a href="https://kwm.me/posts/incidents-an-organizational-swiss-army-knife">key lever for driving continuous improvement and change</a>.</p>

<p><strong>Q: What does your roadmap look like for the coming months or year?</strong></p>

<p>Here I’m listening for initiatives that:</p>

<ul>
  <li>Align with what we do today, where we can satisfy the requirement or meaningfully accelerate progress</li>
  <li>Are on our roadmap, as this helps with prioritization, and reinforces that we have some shared vision</li>
  <li>Include tooling consolidation or platform migrations, which can indicate a natural entry point, or a risk if the consolidation cuts you out</li>
  <li>Aren’t on our radar at all, particularly those that factor into competitive losses</li>
</ul>

<p><strong>Q: If you could add a single skillset to your team today, what would it be? If you could add an entire team, what would you have them do?</strong></p>

<p><em>What do they know they want</em>? Usually, they’ll frame it around a specific, acute problem they can’t solve or solution they can’t build in-house.</p>

<p><strong>Note:</strong> There’s a subtle but important difference between this type of question and “What causes you to lose sleep?” When asked about fears, a mature team will probably name a specific threat or risk. You can then explain how your product addresses it and hope they connect the dots — but unless that fear is your primary point of value, you’ve gone down a rabbit hole and likely missed the broader product story.</p>]]></content><author><name>by Keith McCammon</name></author><category term="Posts" /><summary type="html"><![CDATA[Whether you’re a founder, in sales, an account manager, or in almost any other customer-facing role, the most valuable thing you can do is ask your customers questions, and learn what their goals, incentives, and measures look like.]]></summary></entry><entry><title type="html">Assorted links 2026-03-15</title><link href="https://kwm.me/notes/assorted-links-2026-03-15/" rel="alternate" type="text/html" title="Assorted links 2026-03-15" /><published>2026-03-15T00:00:00+00:00</published><updated>2026-03-15T00:00:00+00:00</updated><id>https://kwm.me/notes/assorted-links-2026-03-15</id><content type="html" xml:base="https://kwm.me/notes/assorted-links-2026-03-15/"><![CDATA[<ol>
  <li>
    <p><a href="https://antithesis.com/blog/2026/carcinization/">A fighting retreat</a> - An email from Will Wilson (CEO and co-founder of Antithesis) to his company, on delaying the inevitable change that occurs when a startup experiences significant growth.</p>
  </li>
  <li>
    <p><a href="https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/">AI as tradecraft: How threat actors operationalize AI</a> - A solid roundup of adversaries’ various uses for AI throughout the intrusion lifecycle.</p>
  </li>
  <li>
    <p><a href="https://direct.mit.edu/isec/article/50/3/86/135683/Deception-and-Detection-Why-Artificial">Deception and Detection: Why Artificial Intelligence Empowers Cyber Defense over Offense</a> - “Rather than heralding a revolution, AI automation is likely to further tame cyber conflict. Highly skilled human operators, not AI, will be necessary to avoid being detected by AI-empowered defenders.”</p>
  </li>
</ol>]]></content><author><name>by Keith McCammon</name></author><category term="Notes" /><summary type="html"><![CDATA[A fighting retreat - An email from Will Wilson (CEO and co-founder of Antithesis) to his company, on delaying the inevitable change that occurs when a startup experiences significant growth.]]></summary></entry><entry><title type="html">Assorted links 2026-03-11</title><link href="https://kwm.me/notes/assorted-links-2026-03-11/" rel="alternate" type="text/html" title="Assorted links 2026-03-11" /><published>2026-03-11T00:00:00+00:00</published><updated>2026-03-11T00:00:00+00:00</updated><id>https://kwm.me/notes/assorted-links-2026-03-11</id><content type="html" xml:base="https://kwm.me/notes/assorted-links-2026-03-11/"><![CDATA[<ol>
  <li>
    <p>$ <a href="https://www.derekthompson.org/p/why-ai-is-not-particularly-good-at">Why AI Is ‘Not Particularly Good’ at Curing Disease (Plus: The Next GLP-1 Boom and Why America Hates Big Pharma): A wide-ranging interview with Dave Ricks, the CEO of Eli Lilly</a> - Pound for pound, Derek Thompson may be my most valuable Substack or newsletter subsription. I learned so much from this.</p>
  </li>
  <li>
    <p><a href="https://paulgraham.com/brandage.html">The Brand Age</a> - “One obvious lesson is to stay away from brand. Indeed it’s probably a good idea not just to avoid buying brand, but to avoid selling it too. Sure, you might be able to make money this way — though I bet it’s harder than it looks — but pushing people’s brand buttons is just not a good problem to work on, and it’s hard to do good work without a good problem.”</p>
  </li>
  <li>
    <p><a href="https://signal.returnonsecurity.com/">The Signal: The cybersecurity economy, charted.</a> - “Real-time venture funding, M&amp;A, and market intelligence across thousands of companies and investors in the global cybersecurity industry. The market intelligence platform behind the Return on Security briefing.”</p>
  </li>
  <li>
    <p><a href="https://marginalrevolution.com/marginalrevolution/2026/03/the-hidden-cost-of-hard-to-fire-labor-laws-why-european-firms-dont-take-risks.html">The Hidden Cost of Hard-to-Fire Labor Laws: Why European Firms Don’t Take Risks</a> - Related to items I shared <a href="https://kwm.me/notes/assorted-links-2026-02-23/">back in February</a>.</p>
  </li>
</ol>]]></content><author><name>by Keith McCammon</name></author><category term="Notes" /><summary type="html"><![CDATA[$ Why AI Is ‘Not Particularly Good’ at Curing Disease (Plus: The Next GLP-1 Boom and Why America Hates Big Pharma): A wide-ranging interview with Dave Ricks, the CEO of Eli Lilly - Pound for pound, Derek Thompson may be my most valuable Substack or newsletter subsription. I learned so much from this.]]></summary></entry><entry><title type="html">Assorted links 2026-02-24</title><link href="https://kwm.me/notes/assorted-links-2026-02-24/" rel="alternate" type="text/html" title="Assorted links 2026-02-24" /><published>2026-02-24T00:00:00+00:00</published><updated>2026-02-24T00:00:00+00:00</updated><id>https://kwm.me/notes/assorted-links-2026-02-24</id><content type="html" xml:base="https://kwm.me/notes/assorted-links-2026-02-24/"><![CDATA[<ol>
  <li>
    <p><a href="https://www.ben-evans.com/benedictevans/2026/2/19/how-will-openai-compete-nkg2x">How will OpenAI compete?</a> - “OpenAI has some big questions. It doesn’t have unique tech. It has a big user base, but with limited engagement and stickiness and no network effect. The incumbents have matched the tech and are leveraging their product and distribution. And a lot of the value and leverage will come from new experiences that haven’t been invented yet, and it can’t invent all of those itself. What’s the plan?”</p>
  </li>
  <li>
    <p><a href="https://larahogan.me/blog/be-a-thermostat-not-a-thermometer/">Be a thermostat, not a thermometer</a> - Solid life advice, disguised as employment (and management) advice.</p>
  </li>
  <li>
    <p><a href="https://steveblank.com/2026/02/24/time-to-move-on-the-reason-relationships-end/">Time to Move On – The Reason Relationships End</a></p>
  </li>
</ol>]]></content><author><name>by Keith McCammon</name></author><category term="Notes" /><summary type="html"><![CDATA[How will OpenAI compete? - “OpenAI has some big questions. It doesn’t have unique tech. It has a big user base, but with limited engagement and stickiness and no network effect. The incumbents have matched the tech and are leveraging their product and distribution. And a lot of the value and leverage will come from new experiences that haven’t been invented yet, and it can’t invent all of those itself. What’s the plan?”]]></summary></entry></feed>