Quote for the day:
"What you leave out is just as important as what you leave in." -- Jason Fried
Post-quantum cryptography adoption and the national security implications
As quantum computers rapidly advance, they are turning theoretical
vulnerabilities in modern encryption into immediate real-world threats.
Experts warn that the transition to post-quantum cryptography must begin
today, even if fully capable systems remain several years away. Because
building these massive machines requires immense capital and infrastructure,
their use will largely be restricted to nation-states and powerful
corporations rather than everyday cybercriminals. This dynamic creates a
severe national security risk. Hostile governments can routinely harvest
encrypted data right now with the clear intention of decrypting it later when
the technology fully matures. While large banks and federal agencies will
likely prioritize upgrading their defenses, smaller targets like local
utilities, regional hospitals, and critical manufacturing facilities often
lack the resources or perceived risk to invest in new security standards. This
leaves a dangerous gap in collective defense that state-sponsored actors can
exploit for economic espionage or infrastructure disruption. To combat this
uneven landscape, experts suggest enforcing strict government mandates,
integrating updated algorithms by default into cloud services, increasing
executive awareness, and expanding academic training. Addressing these
vulnerabilities early ensures that critical networks remain secure, proving
that immediate preparation is absolutely essential for long-term national
security.The need to fortify cloud integrity as cracks increase
As organizations rapidly integrate artificial intelligence and complex networking models, managing cloud security is becoming increasingly difficult. Jim Reavis, chief executive of the Cloud Security Alliance, notes that while modern cloud technology is highly capable, the operating structures surrounding it remain fragmented and messy. A major recurring issue is the shared responsibility model. Many companies mistakenly assume their cloud providers handle all security, yet customers often carry the bulk of the burden for protecting their data, applications, and user identities. The rapid rise of artificial intelligence complicates this further. Because these predictive tools are prone to errors and unintended actions, companies must establish clear boundaries, defined goals, and strict oversight rather than expecting the technology to police itself. Reavis highlights the concept of limiting automated systems by introducing strict autonomy rules, ensuring they only perform specific, approved tasks to prevent accidental damage or data loss caused by simple misconfigurations. Furthermore, outdated operational technology and disconnected internal teams create dangerous blind spots. When security, risk, and development departments operate in isolation, they leave cracks that intruders easily exploit. To safely adopt new capabilities, businesses must modernize their structural operations, unify their risk management strategies, and consistently maintain human control across their digital systems.What AI Is Revealing About Your Bank’s Transformation
Financial institutions are moving artificial intelligence from testing phases
into daily operations, but this shift is exposing hidden flaws in how these
organizations function. The technology itself is not creating new problems;
rather, it is shining a light on old, unresolved issues from past attempts to
modernize. Many banks upgraded their digital tools over the years while
leaving their internal departments disconnected. Because these separate
systems do not share information smoothly, the resulting environment is too
fragmented for advanced tools to work properly. As a result, companies
discover that while their new technology is ready to go, their internal
foundations are not. Banks that previously took the time to truly connect
their systems are now seeing clear, measurable benefits. Meanwhile, those that
simply pasted new tools over old habits are struggling to see real value. The
focus is now moving away from programs that simply offer advice toward systems
that actively manage routine tasks. To succeed today, these banks must stop
viewing this as just a technology issue and recognize it as a fundamental
operational challenge. Strengthening their internal foundations will allow
them to actually improve customer experiences and stay ahead in the market.Backlogs? Where We’re Going We Don’t Need Backlogs
This episode of the CISO Series Podcast features producer David Spark and
co-host Steve Zalewski alongside Varsha Agrawal, head of information security
at Prosper Marketplace. They explore the challenging reality of artificial
intelligence vendors and the growing issue of lock-in. While businesses hope
AI will seamlessly clear backlogs and save time, attendees at AI summits often
leave with more questions than answers, realizing no magical solution
currently exists. The hosts discuss the risk of handing over critical
workflows, customer experiences, and data models to external vendors whose
incentives might suddenly shift. Agrawal argues that vendor lock-in with AI is
uniquely unpredictable because pricing models and the very existence of the
tools frequently change, making it impossible to evaluate long-term costs
upfront. She highlights that lock-in extends beyond data and contracts—it
deeply affects employees who become accustomed to specific tools and
workflows. Instead of blindly trusting AI solutions, the panel stresses the
importance of having confidence in a system's constraints and building
organizational readiness to switch tools when necessary. Furthermore, the
episode briefly touches on boardroom communication, noting that true security
governance requires boards to ask critical questions about detection and
recovery rather than relying on oversimplified dashboards.
Leap second proposal will keep software stacks in sync
Global timekeeping experts are preparing to vote on a crucial proposal to end
the practice of adding or subtracting leap seconds to Coordinated Universal
Time. For decades, scientists added leap seconds to keep atomic clocks
synchronized with the Earth's gradually slowing rotation. However, because the
planet's rotation has recently accelerated, timekeepers now face the
unprecedented prospect of applying a negative leap second. This poses a
significant threat to global digital infrastructure. Computer systems,
databases, and interconnected software applications were never designed to
subtract time, and doing so could trigger widespread system failures, database
corruption, and major outages across financial networks and cloud platforms.
To prevent these risks, the General Conference on Weights and Measures will
vote to make coordinated time continuous starting in May 2027. This change
would allow atomic time to drift slightly from the Earth's physical rotation
over centuries, up to a maximum of one hour. Technology analysts strongly
support this transition, arguing that preserving exact astronomical time
synchronization is no longer worth the severe operational risks to modern
enterprise technology. Passing the proposal ensures long term stability and
predictability for the countless computer systems that run our highly
connected modern world.Beyond shared responsibility: When AI acts, who owns the blast radius?
As artificial intelligence evolves from answering questions to actively
executing tasks, the traditional shared-responsibility models used for cloud
computing are no longer sufficient. Cloud security models historically divided
duties by infrastructure layers, with vendors securing the environment and
customers securing their data. However, agentic AI operates differently,
distributing authority across complex chains of models, platforms, and
partners at machine speeds. Today, an AI agent might possess legitimate access
and permissions but still produce unintended or harmful business outcomes,
separating authorization from the actual intent and final result. Because
these systems now hold agency within business processes—capable of accessing
data, calling tools, and executing thousands of steps autonomously—the
industry desperately needs a new shared-accountability framework. This
emerging model must clearly define who authorizes actions, who can intervene,
and who ultimately owns the consequences when something goes wrong. Security
platforms are racing to become the control layer, aiming to validate identity
and contain runtime behaviors. Yet, organizations remain accountable for
defining acceptable outcomes and managing recovery when AI systems trigger
unforeseen events. Ultimately, establishing clear ownership across every
automated handoff is critical before deploying these powerful, independent
agents into production environments.
Retail colo in the age of AI: One size does not fit all
The rapid expansion of artificial intelligence is fundamentally changing how
retail colocation data centers operate around the world, proving that
standardized infrastructure is no longer sufficient. Historically, colocation
providers offered uniform spaces with predictable power and cooling limits,
which worked perfectly for traditional enterprise applications. However,
artificial intelligence introduces workloads that demand significantly higher
power density and advanced cooling methods, such as liquid cooling systems.
Providers are realizing that a single operational model cannot accommodate
these extreme variations. While some customers require massive clusters for
training complex models, others need smaller setups closer to end users for
swift inference tasks. Consequently, retail colocation facilities must become
much more flexible. They need to redesign their environments to support
diverse requirements within the same building, balancing specialized zones
with traditional racks. This essential shift requires strategic investments in
upgraded power distribution and innovative thermal management systems. By
moving away from rigid approaches, data center operators can successfully
cater to the unique demands of artificial intelligence without alienating
their conventional enterprise clients. Ultimately, embracing true adaptability
allows colocation providers to remain competitive, ensuring they can support
the next generation of computing while maintaining sustainable and highly
efficient operations across their diverse customer base.80% of AI projects fail, and Gallagher’s India CIO says he knows why
Many enterprise artificial intelligence initiatives fall short of expectations
because companies focus on the technology rather than the core business
problem. According to Julen Mohanty, a technology leader at the insurance firm
Gallagher, roughly 80% of AI projects fail for this exact reason. Instead of
finding a practical use case that increases revenue, reduces costs, or manages
risk, organizations often adopt the latest tools and then search for places to
apply them. Similarly, starting a project simply to reduce headcount is a
misguided approach. The real goal should be to improve the underlying process.
While automation can drastically speed up tasks like proposal generation and
claims processing, human oversight remains vital. Machines can perform
repetitive work efficiently, but accountability must always rest with people.
A successful strategy requires measuring a process before automating it to
ensure real efficiency gains are possible. Furthermore, robust data governance
must come first, as data is only valuable when a company knows how to connect
it to a specific outcome. Ultimately, a collaborative company culture and
strong security controls are just as important as the chosen platform. By
keeping humans in the loop and solving real problems, businesses can implement
these advanced systems successfully.
AI note-taking applications have become popular workplace tools for recording
meetings and generating helpful summaries, but their rapid rise has sparked
significant privacy concerns and complex legal challenges. According to
attorney Brian McGinnis, multiple lawsuits against vendors like Otter,
Fireflies, and Granola focus on whether these tools unlawfully capture
communications without adequate notice or proper consent. A major issue is how
conversation data is subsequently processed, particularly if it is used to
train AI models or create highly regulated biometric voiceprints. These
specific practices potentially violate federal wiretapping statutes and strict
state laws, such as the Illinois Biometric Information Privacy Act and
California's two-party consent rules, which require every single participant
to agree to being recorded. While an outright ban on AI notetakers is highly
unlikely, companies face substantial risks if they allow employees to freely
deploy these applications without clear operational guidelines. To mitigate
legal exposure, McGinnis advises organizations to establish comprehensive
internal policies governing AI usage. Businesses should ensure employees only
use approved tools, enable all built-in notice features, and strictly obtain
explicit consent from all meeting participants before recording begins. As the
technology expands into wearable devices, navigating the complex rules around
privacy and recording consent will remain a critical, ongoing challenge for
employers.
AI notetakers at work could leave companies at risk for lawsuits
AI note-taking applications have become popular workplace tools for recording
meetings and generating helpful summaries, but their rapid rise has sparked
significant privacy concerns and complex legal challenges. According to
attorney Brian McGinnis, multiple lawsuits against vendors like Otter,
Fireflies, and Granola focus on whether these tools unlawfully capture
communications without adequate notice or proper consent. A major issue is how
conversation data is subsequently processed, particularly if it is used to
train AI models or create highly regulated biometric voiceprints. These
specific practices potentially violate federal wiretapping statutes and strict
state laws, such as the Illinois Biometric Information Privacy Act and
California's two-party consent rules, which require every single participant
to agree to being recorded. While an outright ban on AI notetakers is highly
unlikely, companies face substantial risks if they allow employees to freely
deploy these applications without clear operational guidelines. To mitigate
legal exposure, McGinnis advises organizations to establish comprehensive
internal policies governing AI usage. Businesses should ensure employees only
use approved tools, enable all built-in notice features, and strictly obtain
explicit consent from all meeting participants before recording begins. As the
technology expands into wearable devices, navigating the complex rules around
privacy and recording consent will remain a critical, ongoing challenge for
employers.The five important tools for controlling AI costs
As generative artificial intelligence becomes a standard feature in modern
software applications, managing the associated computing costs has become a
critical challenge for engineering teams. Fortunately, there are five
practical methods to keep these expenses under control without sacrificing
overall performance. First, teams should use model routing, which directs
simpler tasks to smaller, cheaper models rather than relying on the most
powerful, expensive option for everything. Second, semantic caching helps by
identifying identical user intents, even when phrased differently, and serving
previously stored answers to bypass the AI entirely. Third, prompt caching
allows developers to keep essential background data stored directly in the AI
engine's memory, eliminating the need to repeatedly send and pay for the same
context. Fourth, practicing prompt discipline through data filtering ensures
that only the most relevant information reaches the AI, which cuts down on
wasteful input charges. Finally, setting strict response constraints forces
the AI to output exactly what is needed, like pure data, instead of generating
polite but expensive conversational filler. By implementing these five core
strategies, developers can build smart, reliable tools while maintaining a
firm grip on their budgets, ensuring that technological progress does not lead
to unexpected financial strain over time.

















