When AI agents gain access, skills become part of the attack surface.
How to frame permissions, approvals, and boundaries before agentic workflows move into production.
Cybersecurity risk · AI security · cloud security
Practical cybersecurity analysis for leaders who need to turn changing threats, technology, and requirements into defensible action.
Explore intelligenceCybersecurity news is abundant. Useful context is not. This site connects real-world events, security practices, and emerging technology to the questions organizations actually need to answer: what happened, why it matters, where the exposure may be, and what to consider next.
Cybersecurity Intelligence
Incident analysis and practitioner-oriented perspective—not a news feed.
How to frame permissions, approvals, and boundaries before agentic workflows move into production.
Technical debt meets identity governance: the control gaps that often stay hidden until an incident.
Security foundations that make cloud risk visible, governable, and easier to improve.
Core perspectives
Start from the area that matches the decision in front of you.
Events and developments, translated into organizational relevance.
Governance, risk, and safeguards for AI systems and agentic work.
Practical cloud security foundations, with a focus on AWS.
What leading frameworks require—and how they inform action.
Where security technologies fit, the risks they address, and the tradeoffs.
A risk-centered perspective built around practical, business-aware security.
Frameworks & regulations
Technology & vendors
Clear, independent explanations of where platforms fit in a layered security program.
Privileged access and identity governance: different control problems that must work together.
Understanding cloud posture, workload exposure, and ownership across a shared-responsibility model.
Endpoint and security operations capabilities that turn telemetry into response.
About Matt
I work across cybersecurity risk, governance, technologies, and operating practices. My focus is helping leaders make sense of a complex security environment and connect it to clear, proportionate action.
The perspectives on this site distinguish between established research, leading practice, and personal experience—because credibility depends on being clear about the source of a point of view.
Connect with Matt