<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CISO Expert</title>
    <link>https://cisoexpert.com/</link>
    <description>Cybersecurity leadership, strategy, and the human side of information security.</description>
    <language>en</language>
    <atom:link href="https://cisoexpert.com/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Your Decisions Are the Bottleneck, Not Your AI</title>
      <link>https://cisoexpert.com/blog/your-decisions-are-the-bottleneck</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/your-decisions-are-the-bottleneck</guid>
      <description>AI can do security work in seconds, but the work still waits in queues and SLAs built for human speed. Compare each SLA with how fast AI can do the same step, automate the steps that need no judgment, and set clear rules for when containment blocks and when it goes to a person.</description>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How Do Security Leaders Learn to Talk Business? An Open Question</title>
      <link>https://cisoexpert.com/blog/how-to-talk-like-a-ciso-the-language-of-business</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/how-to-talk-like-a-ciso-the-language-of-business</guid>
      <description>Security leaders lose decisions when they report on controls instead of choices. A question-stage note: why I think the translation fails, what the SEC's 2023 rule implies about who carries it, and a way to start practising this week.</description>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Mountain Maturity Communication Model</title>
      <link>https://cisoexpert.com/frameworks/mountain-maturity</link>
      <guid isPermaLink="true">https://cisoexpert.com/frameworks/mountain-maturity</guid>
      <description>A mountain-climbing analogy that translates NIST CSF maturity levels into a five-stage narrative — Basecamp through Summit Standard — that boards and executives grasp without a framework briefing.</description>
      <pubDate>Mon, 21 Sep 2026 18:00:00 GMT</pubDate>
    </item>
    <item>
      <title>I Scanned 16 MCP Servers for Safety Hints. The Scanner Flagged Every One.</title>
      <link>https://cisoexpert.com/blog/mcp-annotation-gap-ecosystem-analysis</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/mcp-annotation-gap-ecosystem-analysis</guid>
      <description>On 2026-05-21 I scanned 16 public MCP servers for tool annotations, the hints agent clients use to decide when a human approves an action. The scanner flagged all 16, and one of those results is wrong. Here is what the gap means for approval gates, and what to check before you adopt a server.</description>
      <pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What AI Is Actually Doing in Your SOC — and What It Shouldn't Be Doing Yet</title>
      <link>https://cisoexpert.com/blog/2026-04-27-what-ai-should-shouldnt-do-in-your-soc</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/2026-04-27-what-ai-should-shouldnt-do-in-your-soc</guid>
      <description>Only 9% of security practitioners are &quot;very confident&quot; in AI-generated alerts — yet adoption is accelerating. The gap comes down to a distinction the demos never make: AI at decision points in a workflow is not the same as AI replacing the workflow. Here is which use cases earn their keep.</description>
      <pubDate>Mon, 27 Apr 2026 19:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Your Data Lake Is Only as Useful as Its Ability to Answer a Question</title>
      <link>https://cisoexpert.com/blog/2026-04-09-data-lake-searchability-architecture</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/2026-04-09-data-lake-searchability-architecture</guid>
      <description>You moved security data to a lake and cut costs. Then an investigation hit and your team spent two weeks finding what should have taken hours. The difference between a cheap archive and a queryable security asset comes down to three architecture decisions most organizations haven't made yet.</description>
      <pubDate>Thu, 09 Apr 2026 19:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Claude Code Doesn't Know What Time It Is — So I Fixed It</title>
      <link>https://cisoexpert.com/tools/claude-prompt-timer</link>
      <guid isPermaLink="true">https://cisoexpert.com/tools/claude-prompt-timer</guid>
      <description>Claude Code can't tell whether you left for two minutes or eight hours, so it picks up stale threads as if nothing changed. claude-prompt-timer is a small hook that tells it how long you've been away. Install it in three steps and confirm it works in one.</description>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The SIEM Cost Trap — Why Your Data Lake + AI Agents Will Win</title>
      <link>https://cisoexpert.com/blog/2026-04-01-siem-cost-trap-data-lake-ai-agents</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/2026-04-01-siem-cost-trap-data-lake-ai-agents</guid>
      <description>The per-gigabyte SIEM pricing model punishes growth. A tiered architecture — hot data for detection, cold storage in a data lake, AI agents bridging the gap — breaks the cost trap without sacrificing security outcomes. Here's how to make the case to your leadership.</description>
      <pubDate>Wed, 01 Apr 2026 19:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The Math Problem AI Just Changed for Security Testing</title>
      <link>https://cisoexpert.com/blog/2026-03-22-ai-pen-testing-rsa2026</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/2026-03-22-ai-pen-testing-rsa2026</guid>
      <description>Security testing has always been an economics problem: defenders can only test what they can afford to test. AI changed the cost of testing, and that changes which assumptions about coverage still hold.</description>
      <pubDate>Sun, 22 Mar 2026 19:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Four Generations of Broken Promises: Why AI SOC Agents Might Actually Be Different</title>
      <link>https://cisoexpert.com/blog/2026-03-18-four-generations-broken-promises</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/2026-03-18-four-generations-broken-promises</guid>
      <description>Three generations of security tooling promised to fix the analyst shortage. All three failed. The fourth — AI SOC Agents — operates on a different principle, but CISOs who ignore twenty years of lessons will repeat the same expensive mistakes.</description>
      <pubDate>Wed, 18 Mar 2026 19:00:00 GMT</pubDate>
    </item>
    <item>
      <title>I Scanned 152 Files of My Own AI-Generated Code for Invisible Unicode Malware</title>
      <link>https://cisoexpert.com/blog/2026-03-17-glassworm-invisible-unicode-ai-code-scanner</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/2026-03-17-glassworm-invisible-unicode-ai-code-scanner</guid>
      <description>GlassWorm hid malicious code in invisible Unicode characters. I scanned 152 files of my own AI-generated code to see whether the same trick was already sitting in my repositories — and built a pre-commit check from what I found.</description>
      <pubDate>Tue, 17 Mar 2026 19:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Claude Code Has Two New CVEs — Here's What They Exploit and How to Harden Your Setup</title>
      <link>https://cisoexpert.com/blog/2026-03-04-the-claude-code-cves-hit-close-to-home</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/2026-03-04-the-claude-code-cves-hit-close-to-home</guid>
      <description>Check Point disclosed two Claude Code CVEs exploiting hooks and MCP config files. Here's what the attack chains look like and how to harden your environment.</description>
      <pubDate>Wed, 04 Mar 2026 19:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How I Made Claude Code Safer (And You Can Too)</title>
      <link>https://cisoexpert.com/blog/how-i-made-claude-code-safer-and-you-can-too</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/how-i-made-claude-code-safer-and-you-can-too</guid>
      <description>Claude Code validates which tools can run, not what they write. That gap cost me a crashed project and a malformed config file — so I built a plugin that validates content before it hits disk, and it turned out to teach Claude to stop repeating the same mistakes.</description>
      <pubDate>Tue, 10 Feb 2026 19:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Document Guard</title>
      <link>https://cisoexpert.com/tools/document-guard</link>
      <guid isPermaLink="true">https://cisoexpert.com/tools/document-guard</guid>
      <description>An open-source Claude Code plugin that inspects every file edit before it hits disk — catching credential leaks, silently dropped Markdown sections, and broken configs that permission rules alone don't stop.</description>
      <pubDate>Tue, 10 Feb 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>I Ran 849 Tests on AI Context Files. Here's What Actually Works.</title>
      <link>https://cisoexpert.com/blog/i-ran-849-tests-on-ai-context-files-heres-what-actually-works</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/i-ran-849-tests-on-ai-context-files-heres-what-actually-works</guid>
      <description>849 controlled tests across three corpus sizes and five folder structures found that a single flat folder with descriptive filenames beats nested hierarchies at every scale — and that keyword or summary indexes actively hurt accuracy once a corpus passes 300K words.</description>
      <pubDate>Thu, 05 Feb 2026 19:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Pre-Selection Beats Post-Selection: How I Made Claude Code 10-30x Faster</title>
      <link>https://cisoexpert.com/blog/how-i-made-claude-code-10-30x-faster-with-pre-selection-hooks</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/how-i-made-claude-code-10-30x-faster-with-pre-selection-hooks</guid>
      <description>Guidance that arrives before a decision beats guidance buried in instructions. By intercepting tool choices before they happen, I cut code-navigation searches from ~300ms to ~50ms — a 10-30x improvement that compounds across hundreds of searches a day.</description>
      <pubDate>Wed, 04 Feb 2026 19:00:00 GMT</pubDate>
    </item>
    <item>
      <title>4 Essentials for Executive &amp; Business Buyin on your Incident Response Plan</title>
      <link>https://cisoexpert.com/blog/4-essentials-for-executive-business-buyin-on-your-incident-response-plan</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/4-essentials-for-executive-business-buyin-on-your-incident-response-plan</guid>
      <description>Four things an incident response plan needs before executives will stand behind it: response SLAs the business agrees to, a clear split between operational and strategic plans, formalization of processes you already run rather than net-new invention, and a signature from the C-suite.</description>
      <pubDate>Fri, 23 Dec 2022 05:51:26 GMT</pubDate>
    </item>
    <item>
      <title>The CyberSecurity &amp; Evolving Threats</title>
      <link>https://cisoexpert.com/blog/the-cybersecurity-evolving-threats</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/the-cybersecurity-evolving-threats</guid>
      <description>A general-audience tour of the threats that dominated 2022 — ransomware, malware, and phishing — and the baseline controls that reduce exposure to them.</description>
      <pubDate>Fri, 23 Dec 2022 05:15:36 GMT</pubDate>
    </item>
    <item>
      <title>Top 5 things for a Successful Cyber Response 'IR' Plan</title>
      <link>https://cisoexpert.com/blog/top-5-things-for-a-successful-cyber-response-ir-plan</link>
      <guid isPermaLink="true">https://cisoexpert.com/blog/top-5-things-for-a-successful-cyber-response-ir-plan</guid>
      <description>Having an incident response plan at all is associated with a 43% reduction in breach cost. Here are the five things that separate a plan that holds up under pressure from one that sits unread — with practical examples for each.</description>
      <pubDate>Wed, 12 Jan 2022 01:02:00 GMT</pubDate>
    </item>
  </channel>
</rss>
