For most of its history, cybersecurity has been arguing with optimists.
When technologists wanted to move too quickly, bypass controls, or treat security as needless overhead, we asked them to slow down. Create safe environments, monitor behavior, prepare for failure, and so on.
The worst parts of our industry did this through FUD (fear, uncertainty, and doubt). The best parts built secure ways to operate. They worked alongside engineering teams, developed useful tools, shared practical guidance, and helped shape regulation.
That approach largely worked. Security now receives meaningful attention and resources at most consequential companies. The pre-AI world was hardly secure, but we developed broadly useful models for managing technological risk.
Over the past few months, though, the conversation has changed. This time, Cybersecurity is not primarily arguing with people who believe bad outcomes are unlikely. We are confronting the world’s most prominent technologists who put substantial odds on catastrophic outcomes. Our current narrative is built for the opposite audience.
The security industry’s initial response has largely been to go along for the ride. That may be good for business in the short term (stonks are stonking :P). Fear increases budgets, makes cuts harder to justify, and attracts investment. But the longer this continues, the more uncomfortable I become with our response.
AI may be the most consequential technology of our time; it also introduces serious security risks (name any consequential technology that did not also create safety and security risks). The response needs to be less “we are doomed” and more “here’s what we can do to solve problems”. If you always think of the worst case without thinking through how likely it is and how we can avoid it, we would have stopped making technological progress a long time ago.
The best security work is often transparent and understated; what we have right now is loud and opaque (saying there is a 10% chance of human extinction is fine, but can you tell us what assumptions produce that number, and what evidence would change it?).
We need more Cybersecurity leaders (practitioners and builders) talking calmly about security and showing their work (more tooling, more write-ups, more amazing conference talks, more ways to operate securely). In other words, lean into the best parts of our industry instead of just going along with the doomers because it’s convenient in the short term.
That’s it for today! Starting with this edition, I am trying out a new format of short posts that may be outside the strict confines of AppSec. I’d love to hear your thoughts on the format. Should I keep going down this road? You can message me on Twitter (or whatever it is called these days), LinkedIn, or email. I am also the co-founder of Seezo. We help companies automate security design reviews at scale. Check us out if that’s your thing :) If you find this newsletter useful, share it with a friend or colleague, or post it on social media.

