ai · security · skills

ai · security · skills

AI is already replacing repetitive security workflows, not the engineers.

Not the engineers, but their old way of working.

Watch what happens to a security org as autonomy climbs, then find your own seat in it.

The Monday it all changesMastery keeping pace

Manual: Humans do the work end-to-end; AI plays no part in the loop. Tap a seat to see what it is made of.

For you

Find your seat. See what it converts into.

Nine seats, a two-minute mastery check, and the skills that close your gap. Nothing saved, nothing asked.

Build the defender’s skills →

For your organization

Measure the function. Gate the climb.

Two ladders per function: how far AI has been adopted, and how well it is governed. The second one holds the first back.

Pressure-test the function →

A function climbs autonomy only as fast as its people climb mastery.

That is the rule this practice is built on, and it holds both stories honest.

Its latest, human-reviewed

New From the practice · 22 Aug 2026

Forrester advises organizations to turn AEGIS controls into an agentic AI security stack rather than treating AI security as an afterthought

AI agent deployments introduce new control requirements that existing security frameworks may not cover, and organizations need a structured model to map controls to agent-specific risks

New From the practice · 23 Aug 2026

CCS Proxy v1.3.0 provides an inline MCP security proxy with three-layer cryptographic attestation including admission verification, protocol attestation, and execution binding

As MCP adoption grows in AI agent architectures, unauthorized tool access through MCP servers becomes a critical attack vector requiring cryptographic enforcement

New From the field · 23 Aug 2026

Dutch regulator fines Uber 825 million euros for allowing algorithms to automatically deactivate driver accounts without adequate human oversight

This precedent shows regulators will impose substantial penalties for automated AI decision systems that lack human review and due process, making algorithmic accountability a compliance requirement

Cloud Security Alliance AI Controls Matrix · NIST AI Risk Management Framework · ISO/IEC 42001 · OWASP LLM Top 10 · MITRE ATLAS

Ask, anywhere

This site answers questions. Ask it one.

The mark in the corner is Hermes, the guide. It knows where everything lives, answers four control questions outright, and signed in it takes a question of your own.

For members

Signing in opens the working parts.

Any Google account works, free, and nothing here is for sale. Everything that argues is already public; these three are what a member adds.

01

The mastery ladder: every seat, scored against real rungs, not a self-report.

02

The explainer answering a question you type, rather than the worked example.

03

AI analysis on your own assessment run.

Sign in with Google →

Nobody lost a job. Everybody got a different one.

The part that was never in the job description is the part this practice teaches.

Score your mastery →

One thing changed this week. Here is what to learn.

A WhatsApp broadcast, one post a week. Nobody sees your number, and you can leave with one tap.

Join the weekly signal on WhatsApp →