Topic
Security
My writing, talks, podcasts, and projects about Security.
Selected work
Nir Soudry — Head of R&D at 7AI
AI vs. AI — how autonomous attackers are scaling phishing and malware, how defenders can use agents to cut alert noise, and where accountability belongs when AI investigates and remediates incidents.
Speed vs. Risk: Experts Weigh In on Using AI Coding Assistants
Engineering leaders discuss when AI coding assistants accelerate development and when they introduce security, quality, and architectural risk.
Half of Kubernetes Clusters Are About to Lose Security Updates
A deep dive into the Kubernetes support lifecycle and what it means for the massive number of clusters running end-of-life versions.
Kubernetes 1.34: Security, Performance, and DRA Go GA
Release lead Vyom Yadav unpacks 58+ enhancements: DRA GA for GPU workloads, mutating admission policies, and major API server performance gains.
AI Security Demo Night w/ Rootly AI, Okta, Panther, Tailscale & More
Live demos at Okta HQ in San Francisco — presenting Rootly AI alongside cybersecurity startups tackling identity, endpoint security, and threat response.
Brian Shaw — SVP of Infrastructure and Core Banking
Building and operating core banking infrastructure with a focus on uptime and regulatory compliance.
Ryan Lockard — VP of Platform Engineering at CVS Health
Platform engineering at healthcare scale — compliance, reliability, and developer experience.
Navigating DORA: A Guide to the EU's Digital Operational Resilience Act
Breaking down the EU's Digital Operational Resilience Act — what it means for financial services and tech companies operating in Europe.
Uplevelling Your Container Lifecycle Management
Best practices for managing the full container lifecycle — from build to runtime to decommission.
Dependency and Runtime Management
Strategies for managing dependencies and runtimes in containerized environments — keeping images secure and up to date.
The Changing Face of Election Security
How election infrastructure security is evolving — from paper ballots to digital voting systems and the role of data compliance.
APRA (American Privacy Rights Act) Explained
A walkthrough of the American Privacy Rights Act — its scope, requirements, and implications for tech companies handling user data.
EU AI Act Secrets Revealed
What the EU AI Act actually requires — risk classifications, compliance timelines, and what it means for AI-driven products.
Intelligent Document Processing Compliance, from Stone Tablets to Digital Docs
The evolution of document processing compliance — from physical records to AI-powered intelligent document processing systems.
Getting started with Platform Engineering security and compliance
How platform engineering teams can embed security and compliance into their internal developer platforms from day one.
Turn data security & compliance into a business advantage
How forward-thinking companies are turning data security and compliance requirements into competitive advantages.
Navigating LLMs challenges in data security & compliance
The unique data security and compliance challenges that large language models introduce — from training data to inference outputs.
No US SaaS for European businesses?
The growing tension between US SaaS providers and European data sovereignty requirements — what it means for cross-Atlantic business.
Private SaaS: a new gold standard?
Exploring the rise of private SaaS deployments as a response to data sovereignty concerns and enterprise security requirements.
4 Ways to Enhance Your Dockerfiles
Practical tips for writing better Dockerfiles — multi-stage builds, layer caching, security scanning, and image optimization.
How does data security impact open-source projects?
The intersection of data security practices and open-source development — challenges, best practices, and community governance.
The Future of Code Quality, Security, and Agility Lies in Machine Learning
How machine learning is transforming code quality assurance, security scanning, and agile development workflows.