🧵 #RSAC got me 🤔. Every major tech platform shift mints new security winners
Network → Cisco. Endpoint → CrowdStrike. Identity → Okta. Cloud → Wiz ($32B exit).
We are now at the start of the next two waves and most organizations aren’t ready.
Here’s what’s coming:
@ayushm_v1 I think the personal assistant market is real and will go through an evolution. Easy tasks first and over time more complicated ones. The question is will meta win the consumer market just from distribution?
Just talked with Sean Adler on The Blue Swan Podcast about AI’s new threat landscape, why I watch the dark web closely, and how cybersecurity founders need investors who move as fast as attackers do.
🎧 https://t.co/RjHlA4GPUL
Going to Black Hat USA 2026 to do normal investor things like take notes in briefings and definitely not get destroyed by the casino floor at 1am with a room full of pentesters.
If you’re building something real in security — AI-native or not — I want to hear about it. DM me.
#BlackHat2026 #Cybersecurity #AI
Everyone is focused on AI writing malware.
JADEPUFFER is a much bigger shift. It reportedly used an AI agent to carry out an entire ransomware attack: initial access and recon to credential theft, lateral movement, and encryption.
That’s a different level of automation.
We’ve been talking about software supply chain risk since SolarWinds. SBOMs, ASPM, secure-by-design. 5 years of frameworks
This week three simultaneous attacks hit security vendors, AI toolchains, and package repos
The category graduated from “important” to “urgent.” There’s a difference
Security is shifting from protecting people and devices to governing identities, machines, and autonomous systems operating at a scale humans can no longer manage manually.
Many paths to Rome & to wealth. Pick one that fits your temperament, time horizon & access. BRK shines at scale, but bigger capital shrinks your options. Warren would’ve crushed it smaller too. Venture is power law: zeros ok when one winner changes everything. Choose & stay the course.
@Larryjamieson_ In 2023 MU was at a cyclical low. Idk how someone would’ve predicted this memory shortage - at least I didn’t. Congrats to those who bought it at the bottom at ~$50 and then held
@SCMagazine@keepersecurity What we are hearing from CISOs is that IGA needs to include both non-human and human identities. Standalone products create silos
Claude Security is now in public beta for Claude Enterprise customers.
Claude scans your codebase for vulnerabilities, validates each finding to cut false positives, and suggests patches you can review and approve.
@nikillinit On the insurance side of things brokers are useful for claims. But agreed, the more complicated the risk, the higher their value. Imagine insuring a rare art piece that has no freely available market data. You will need a specialized broker
@bnafOg CISOs want to narrow the asymmetry gap between defenders and offenders. An offender just needs to be right once to get what they want and a defender needs to be right every time. AI is changing the attack surface rapidly. CISOs have a tough job
Startups are building identity for AI agents. They are faster and more nimble.
Okta just walked in with distribution. See their latest announcement
Can a legacy IdP win the agentic identity category?