AI isn't a strategy.
AI can expand what a business is capable of. Strategy decides which capabilities are worth using, why they matter, and where they should take us.
Read the perspective ↗I’m Jesse. I lead security teams, build games, and ask a lot of questions. These are my thoughts on the work, the technology, and whatever else gets me thinking.
Explore my thinkingAI can expand what a business is capable of. Strategy decides which capabilities are worth using, why they matter, and where they should take us.
Read the perspective ↗AI can expand what a business is capable of. Strategy decides which capabilities are worth using, why they matter, and where they should take us.
AI can identify a real security problem and still recommend the wrong business decision. How do we turn useful analysis into actions we can depend on?
A serious mistake tests more than a system. It tests whether people can tell you the truth, whether ownership means anything, and whether your help leaves the team stronger.
Passkeys remove familiar opportunities to steal and replay credentials. The real security gain depends on how we enroll them, recover access, protect sessions, and retire weaker routes.
Security questions should be retired. SMS, codes, and push each leave different openings. The useful question is which attack your authentication method can actually stop.
Exceptions can keep a business moving. They become harder to resolve when ownership is unclear, the rating understates the exposure, and renewal replaces a real decision.
The host’s phone runs the fight. Cloudflare keeps the party together. How I built private co-op, what batching changed, and the compromises I chose to accept.
The right path to AI adoption combines usable guidance with ownership, bounded permissions, monitoring, and a response that works.
AI agents need clear authority, accountable owners, and access designed around the task they are meant to perform.
The next step for security is to combine AI-driven testing with what we know about our systems, our clients, and how our businesses actually operate.
A locked-out person still needs help. The recovery process must preserve the trust established at sign-in.
A secure-looking component can still rely on a decision made somewhere else. Follow the trust between systems.
Leadership needs a clear view of exposure, progress, and the decisions that will help the business move forward.
A simple explanation of the digital key behind the sign-in, followed by a closer look at the technology that makes it work.
Start with what could go wrong, then make a concrete decision about how the system should work.
Prioritize the exposure that matters, make remediation achievable, and build controls that support dependable delivery.
The most useful security improvement may be the one a delivery team no longer has to remember.
Everyone can be doing their part while a risk stays open. Who has the authority to bring the decision together?
The lasting value of testing is what the organization learns and changes after the report arrives.
Joining, changing roles, and leaving are business events. Access needs to follow them reliably.
No perspectives match. Try another topic or search.

I like understanding how things work, where they can break, and what it takes to make them dependable. My work spans enterprise identity, application security, and offensive security. My perspective comes from the work itself: leading teams, digging into how systems behave, and making decisions when the answers aren’t obvious.
I enjoy the technical detail. I also care about whether a decision makes sense for the people who have to live with it. A control needs to protect something important and work when someone is trying to serve a client, ship software, or get through their day.
I’m curious about AI, especially what it can help us test and build. The business still has to decide where it’s going. I want the technology, and the security around it, to help us get there.
I want to understand what you’re trying to do before I tell you how to secure it. The business needs to keep moving, and my job is to help us make decisions we can explain and live with.
Tell me what you need to get done. Launch a service? Give someone access? Put AI to work? I want to understand who depends on it, what it needs to do, and where we have room to make a different choice. A security requirement should have a reason behind it. If I can’t explain how it helps, I owe you a better answer.
If we’re counting on a control to protect us, I want to see it tested. Try to get past it. Check the recovery path. Ask what happens when an account is compromised or a dependency fails. I’m quite happy to find out my assumptions were wrong while we still have time to do something about them. Then we need to use what we learned to make the system better.
When I bring you a risk, I should be able to explain what could happen, what we know, and where I’m still making assumptions. You deserve my recommendation, too. What would I do, and why? Once we decide, someone needs to own the next step and have the means to follow through. I want the conversation to leave us able to act.
I build games through Wicked Studios. I enjoy taking an idea, getting it to work, and discovering all the things I didn’t think of at the start.