AI = improve cybersecurity & create new exposure...
Both can be true.
Problem:
Most orgs are still trying to measure digital exposure "the old way" that doesn’t answer ONE business question:
How does it impact EBITDA?
Thrivaca was built to close this gap.
#ProtectYourEBITDA
AI is everywhere. But most companies are still stuck in pilot mode.
The issue isn’t the tech. It’s that the work itself hasn’t changed.
Leaders are starting to rethink workflows, roles, and decisions end to end. That’s where the real value is unlocked. https://t.co/ask2NpJfwF
Iran-affiliated cyber actors are targeting operational technology devices across US critical infrastructure, including programmable logic controllers (PLCs). These attacks have led to diminished PLC functionality, manipulation of display data and, in some cases, operational disruption and financial loss.
The @FBI, @CISAGov, @NSAgov, @EPA, @ENERGY and @US_CYBERCOM are urging US organizations—especially municipalities and those in the water and energy sectors—to review the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) detailed in this advisory. Applying the recommended mitigations will reduce the risk of compromise: https://t.co/A4l9U4Ky1b
🚨Just dropped - my latest op/ed at Forbes: "Energy Fortress America: Energy Security Matters Now More Than Ever."
Amid the chaos in the Strait of Hormuz with missiles flying and oil prices spiking past $90/bbl, America's shale boom has us in a strong position. We're weathering this storm better than anyone else thanks to record domestic production and minimal reliance on Persian Gulf imports.
Energy security isn't just about prices—it's national security.
Here's a quick summary:
⚡️ Shale Revolution's Impact: U.S. oil imports from the Gulf are down to ~500k bpd, a massive drop from 3M in 2003. Domestic output hits 13.7M bpd, up 145% since then, turning us into a net exporter via fracking and horizontal drilling in the Permian and Bakken.
⚡️ Policy Acceleration: Trump's energy dominance agenda cut red tape, sped permits, and boosted LNG exports, overcoming ESG hurdles and making us the world's top oil & gas producer. This insulates us from supply shocks that crippled economies in past crises.
⚡️ Resilience Amid Turmoil: With 20% of global oil transiting the Hormuz Strait now disrupted, we avoid the energy noose—though pump prices jumped 20¢/gal. No shortages like the 1970s lines; abundant domestic supply gives the White House leverage against Iran's provocations.
⚡️ Rivals' Vulnerabilities Exposed: Europe's green zeal and nuclear shutdowns leave it dependent and at risk from Putin's threats to cut flows. China's losing 5-6M bpd via Hormuz, plus Venezuelan/Iranian crudes, forcing it to halt refined product exports for domestic needs. Russia shifts east, weakening its grip.
⚡️ U.S. Geopolitical Edge: American LNG fills gaps in Europe and Asia with Qatar offline, reducing Russian influence. Easing sanctions on Russian oil boosts global supply, indirectly benefiting us.
⚡️ Future Outlook: Push production higher with more rigs and tech—despite "peak oil" doomsayers. Sustaining this decouples us from Middle East messes.
In short, America's energy strength is our greatest global advantage as markets churn. Energy security = national security.
Read the full piece here:
https://t.co/CvervG4a1q
#EnergySecurity #ShaleBoom #Oil #EnergyDominance
Very pleased to join my @CSISEnergy colleagues in a collective reaction to events in #Iran -- just published this afternoon: https://t.co/QJ4iEivs1A.
#OOTT
These aren’t isolated #cyber incidents.
They’re signals.
#AI -driven software, faster releases, and invisible dependencies are expanding exposure faster than most leadership teams can see — or explain.
The real risk...👉 explained here: https://t.co/P8MIbtAwtW
#HonorAllWhoServed#Veterans
Discipline, mission focus, accountability — are the same lessons we bring to every #cybersecurity challenge today. Whether it’s defending freedom or digital infrastructure, the principle remains the same: protect those who depend on you.
Too many tools. Too little insight.
65% of orgs say they’re drowning in dashboards that don’t even talk to each other. (Barracuda)
Time to #UNdashboard with Thrivaca™ → clarity > clutter.
#ArxNimbus#WednesdayWisdom
#WedesdayWisdom: Status quo has a cost.
IBM says breaches still cost $4.44M on average—$10.22M in the U.S.
Shadow AI alone adds $670K per incident.
ArxNimbus Thrivaca maps 47,000+ threat ↔ vuln pairings so you can:
Prioritize kill shots,
Quantify financial impact,
Prove ROI
Releasing our Q2 2025 State of AI - China Report 🇨🇳: Chinese AI labs have achieved close to parity with US labs, led by DeepSeek's leap to world #2 in intelligence and backed by a deep ecosystem of 10+ players
Key findings from our analysis:
🇨🇳 The Chinese AI Ecosystem has depth and has demonstrated consistent innovation with DeepSeek and Alibaba now releasing models within weeks of global counterparts, with comparable or superior performance across benchmarks. 10+ Chinese AI labs have models with impressive intelligence scores, including DeepSeek, Alibaba, ByteDance, Tencent, Moonshot, Zhipu, Stepfun, Xiaomi, Baichuan, MiniMax and 01 AI
👐 An open weights approach has supported international adoption: Several Chinese AI labs have embraced strategies of releasing open weights models, allowing broad accessibility and supporting adoption by developers worldwide
🏆 DeepSeek achieves impressive technical breakthroughs, with DeepSeek R1-0528 achieving frontier AI performance. This places it amongst the world's highest-performing models alongside Google's Gemini 2.5 Pro and above models from xAI, Meta, and Anthropic
A highlights version of the report is freely available on the Artificial Analysis website for a limited time.
Below we share key excerpts:
Arximedes has logged on.
“SMBs are not too small to hack.
They’re just too small to recover.”
Weekly truths from the newest brain at #ArxNimbus.
Get the full report: https://t.co/LbTpM2SMcP
#FridayFunny#CyberQuotables#SMBRisk
Perhaps not your idea of a #SundayFunday, but an important #cybersecurity ROI briefing nonetheless.
Justify-Communicate-Measure Impact. Here's how:
https://t.co/8554NYiYW2
💸 Cybersecurity spend is up. Losses are up more.
In a downturn, you don’t need another tool.
You need financial clarity.
Open letter from our CEO: 👉 https://t.co/TkaHAlEb0V
#CFOwin#CISOwin#BoardGovernance#CyberSecurity
#FridayFunny#CyberWakeUpCall
In the world of cyber risk, a T-Score quantifies your organization’s true exposure across financial, operational, and reputational domains.
It’s not a feeling.
It’s not a “heat map.”
It’s actuarial-grade reality.
#YouGetATScore#ArxNimbus
You know what they say about polls…
They’re directional, not definitive.
But when 3 polls point in the same direction—AI needs security guardrails—we listen.
Here's what you can do now to address your risk exposure in #AI 👉 https://t.co/UMULeAs5uo
🚨 Here's Your #FridayFunny#WakeUpCall! 🚨
If your #CyberSecurity estimations are 86% off from reality, it’s time to recalibrate. 📉
Here's how:
https://t.co/UMULeAs5uo
We're not letting up on the Dirty Little Secrets in #cybersecurity, how about this for your #FridayFunny (not funny)?
It’s time for real observability—not just compliance theater. #CyberWakeUpCall https://t.co/UMULeAs5uo
It's time for dirty little secrets — in #cyber:
🚨 Boards are making #cybersecurity decisions based on emoji status reports. Let that sink in. 🚨
Cybersecurity should have the same scrutiny and clarity as other critical business functions. Talk to us! #MetricsMatter.